Video lesson: Authentication, Sessions, and Authorization
Lesson promise
By the end, the learner should be able to explain the core model for authentication, sessions, and authorization, apply it to a concrete input, and identify when its usual shortcut or guarantee stops applying. This is a recording brief; publish it as a playable lesson after the narration and visual sequence have been produced and reviewed.
Narration draft
Authentication answers who or what is making a request; authorization decides which actions that identity may perform on a resource. A session binds later requests to an authenticated context. Keeping these decisions separate makes access rules easier to audit and change.
After login, a server can create a random session identifier and store session state server-side, sending the identifier in a protected cookie. On each request, it resolves the session and checks whether the user may access the requested object. Object ownership must be checked at the resource boundary, not inferred from a hidden UI link.
Signed tokens can reduce lookup needs but complicate revocation, expiration, and claim freshness. Cookies need secure transport and appropriate SameSite and HttpOnly settings. Authentication success alone must never imply permission to read every record associated with a guessed identifier.
Visual sequence
- Put the input and assumptions on screen. Ask the learner to predict the next state before revealing it.
- Animate the representation and show the operation one transition at a time.
- Pause at the boundary case in the companion article and compare the result with the invariant.
- End with the exercise prompt: A user changes a URL from /orders/123 to /orders/124 and sees another account’s order. Identify the missing server-side check and one test that would catch the flaw.
Companion material
Use the article, trace, and interactive concept flow as the learner’s written and visual references. The video remains planned until an actual playable media URL and reviewed transcript are available.
Related articles
Authentication, Sessions, and Authorization
Authentication answers who or what is making a request; authorization decides which actions that identity may perform on a resource.
Latency, Throughput, and the Cost of Coordination
Every system design trade-off is ultimately a balance between doing work fast, doing work often, and paying the cost of making multiple components agree.
What Is a Software System?
A system is not a single program — it is components with boundaries, responsibilities, and failure modes. Learn how to see the box before you design inside it.
New lessons by email
Get new articles and notes on the systems behind everyday software.
One technical dispatch per week. No noise.
Not started
Sign in to save your learning progress.