In revision.

Section 07 of 10

Security & Crypto

HMAC, VAPID, JWT, OAuth, TLS - so the VAPID inversion never happens again.

  1. 7.1

    Public/private key crypto

  2. 7.2

    HMAC signatures

  3. 7.3

    VAPID and web push (the Spur mistake)

  4. 7.4

    JWT tokens

  5. 7.5

    OAuth 2 flows

  6. 7.6

    TLS deep dive

  7. 7.7

    CSRF, XSS, SSRF

  8. 7.8

    OWASP top 10

  9. 7.9

    Webhook signature verification

  10. 7.10

    Secrets management