Os Labs / Security
SecurityWorking~6h
Build a login that survives an attack
A minimal but real authentication flow: signup, login, and a protected route, backed by properly hashed passwords, signed sessions (or JWTs) with sane expiry, CSRF/SameSite protection on state-changing requests, and rate limiting on login attempts. You finish by writing attack scripts against your own service and showing each one fails the way it should.
O que isso prova
A frase que você pode defender em uma entrevista.
Linha do currículo
Implemented a production-pattern auth flow (bcrypt/argon2 password hashing, signed sessions with expiry, CSRF protection via SameSite + token, rate-limited login) and validated it with attack scripts proving brute-force, session-fixation, and CSRF attempts all fail.
- Understands why plaintext/weak-hashed passwords and unbounded login attempts are disqualifying, not stylistic
- Can implement session/token auth correctly, including expiry and invalidation
- Defends state-changing requests against CSRF, not just XSS
- Tests security claims with real attack scripts instead of asserting them
O briefing
O que você constrói, passo a passo.
- 01Build signup/login endpoints that hash passwords with bcrypt or argon2 (never plaintext, never fast general-purpose hashes like MD5/SHA1).
- 02Issue a signed session cookie or JWT on login with a defined expiry and a working logout that invalidates it.
- 03Set cookies with HttpOnly, Secure, and SameSite=Lax/Strict; add a CSRF token check on all state-changing (POST/PUT/DELETE) routes.
- 04Rate-limit the login endpoint per IP/account (e.g. 5 attempts per 60s) and return 429 once exceeded.
- 05Build one protected route that rejects requests with a missing, expired, or tampered session/token.
- 06Write attack scripts: a brute-force login loop, a forged/tampered token request, and a cross-site POST without the CSRF token.
A prova
Está pronto quando estes passarem.
Stored user records contain only hashed passwords — a database dump shows no plaintext or reversible encoding
automated test
The brute-force script is blocked with 429 responses after the configured attempt threshold
automated test
A tampered or expired session/JWT is rejected by the protected route with 401
automated test
A forged cross-site POST without a valid CSRF token is rejected
automated test
Stack
Node/Express or Python/FastAPIbcrypt or argon2a session store or JWT librarya rate limiter (in-memory or Redis)
Método Sage
frame → map → decide → prove
Você mantém
A working auth service + 3 attack scripts + a pass/fail report for each attack