Security
Overview

Security

Designing systems that are secure by default, not by accident.


Topics

ChapterWhat It Covers
Security FundamentalsAuthN vs AuthZ, sessions vs JWTs, OAuth2/OIDC, TLS, encryption at rest vs in transit, secrets management, injection attacks, CORS vs CSRF, rate limiting/DDoS, OWASP Top 10

Why This Matters

Security isn't a checklist you run at the end — it's a set of design constraints that should shape a system from the first whiteboard sketch. Almost every real breach traces back to one of a small number of recurring gaps covered in this chapter, not an exotic attack.