Account security is a chain of independent checks. Password verification establishes one identity claim; a session keeps that claim across requests; recovery can replace it; a federated callback introduces another party; and a server-side fetch can expose internal services if its target is untrusted. Each boundary needs a distinct failure rule and a test that does not depend on the browser hiding controls.
Topics in this track
- Password Verification and Login Budgets — Store slow salted verifiers and bound repeated attempts without revealing account existence.
- Account Recovery and Session Revocation — Make recovery tokens single-use, short-lived, and separate from an active session.
- Federated Login Callback Boundary — Bind an external sign-in response to the browser that began it and verify the identity token.
- Outbound URL Requests and SSRF Boundaries — Keep user-supplied destinations away from private networks and privileged credentials.
Prerequisite paths
Sessions and CSRF: keep identity on the server; Authorization: check permission for this record on every request; Environment Configuration and Secret Boundaries.
Neighbor track
Practice path
Build Project: account access and recovery boundary and check decisions in Web Development: identity and integration contracts quiz.
Further connections
Authorization and Tenant Boundaries; Object-Level Authorization for Reads and Writes.
Further connections
Passkeys and Account Assurance; Passkey Registration Challenge and Credential Binding.
