Authentication, authorization and sessions
Lesson 1 of the module "Knowing who signs in" in the course "Design authentication and permissions for a product".
Lesson objective
By the end of this lesson, you will be able to distinguish authentication, authorization and session, explain what a session cookie and a token (JWT, refresh token) change, and specify your product's session durations, sign-out and access revocation.
Where it fits
Knowing who signs in
How do you verify users' identity, keep their session and give them access back without opening a security hole?
Lessons in this module
- Authentication, authorization and sessions (this lesson)
- Passwords and account recovery
- Two-factor authentication and passkeys
What you will learn in the course
This lesson is part of the course Design authentication and permissions for a product
- Distinguish authentication, authorization and session, and specify session durations, sign-out and access revocation.
- Specify password rules and account recovery journeys following current recommendations (NIST SP 800-63B-4, CNIL, OWASP).
- Choose strong authentication factors (TOTP app, passkeys), plan their rollout and specify the fallback journeys.
- Specify delegated sign-in (OpenID Connect, social login) and enterprise SSO (SAML, OIDC, SCIM provisioning) for a B2B product.
- Design a permission model (roles, attributes, scope) as a roles × actions matrix, enforced on the server side according to least privilege.
- Specify isolation between customers, invitations, the audit log, support access and account deletion.
- Specify your product's complete sign-in journeys, with states and errors, and choose between building and using an authentication provider.
Related courses
- Git for PMs: ship as a team without putting production at riskAdvanced · ~3 hr 30 min
- Explain how a web product works, from browser to serverAll levels · ~2 hr 30 min
- Design and test an API integration as a PMJunior · ~3 hr