Why OAuth: delegation, not authentication
P55.oauth-flows.01 · Audience: guest, it-ml, language-pro · Prerequisites: Public-key crypto & signatures
Welcome to OAuth 2.0 / OIDC & Federated Identity — the first pillar of the Security discipline's Authentication & Identity domain. OAuth is how one app gets delegated access to your account somewhere else without your password. This track drives the authorization-code flow — the backbone of modern sign-in — and the two checks that keep it safe.
Same thread as every module here: concept → protocol → attack → defence. The graded work is
always the defence — here, rejecting a tampered state (the check that stops cross-site request
forgery, CSRF — another site submitting the flow for you) and an unregistered
redirect_uri (open redirect).
The code runs entirely in your browser (Pyodide); nothing leaves your machine.
Ask the mentor about this module
Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.
Keeping your files on this device
Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.
Rung 1 — drive the authorization-code flow
Loading exercise…
My notes on this module
Loading your notes...
Where next?
Later in OAuth Flows