Section 07 of 10
Security & Crypto
HMAC, VAPID, JWT, OAuth, TLS - so the VAPID inversion never happens again.
- 7.1
Public/private key crypto
- 7.2
HMAC signatures
- 7.3
VAPID and web push (the Spur mistake)
- 7.4
JWT tokens
- 7.5
OAuth 2 flows
- 7.6
TLS deep dive
- 7.7
CSRF, XSS, SSRF
- 7.8
OWASP top 10
- 7.9
Webhook signature verification
- 7.10
Secrets management