Two different questions that get merged into one word and cause real breaches.
Auth and Identity
Who you are, what you may do, and where the secrets live.
Authentication is the feature most likely to be quietly wrong in a vibe-coded app, because a broken version looks identical to a working one until someone tries. This course covers the concepts you need to review it honestly.
Start the first lesson0/4 lessons read
By the end you can
- Separate authentication from authorization and check both
- Explain how a site remembers you between stateless requests
- Know what "sign in with Google" is actually doing
- Handle secrets without leaking them
Lessons
How a stateless protocol manages to remember you at all.
What OAuth actually does, and why it is usually the safer choice.
Where keys live, how they leak, and what to do the moment one does.