Phase 6 · Identity, security and hardening
Week 16: Identity and security
Friday deliverable: Threat model and auth features
- Day 1Password hashing with argon2id; sign-up and loginOutline only
- Day 2Sessions and cookies (HttpOnly, Secure, SameSite); CSRFOutline only
- Day 3Roles and access-control tests; audit logOutline only
- Day 4OAuth 2.0 and OIDC flow; JWT trade-offsOutline only
- Day 5STRIDE threat model; Redis rate limiting; idempotency keys on paymentsOutline only