Verify a password without storing it
Understand password hashing, salts, verification cost, and account enumeration.
A session remembers a successful login
Explain opaque cookies, hashed session tokens, expiry, and revocation.
Cookies make browser trust a server concern
Distinguish CSRF protection from CORS and ordinary authorization.
A workspace is the tenant boundary
Separate global users from the organizations that own application data.
Scope every tenant-owned operation
Prevent insecure direct object references with membership checks and scoped queries.
A role belongs to a membership
Understand workspace-specific permissions and the safety of administrative changes.
An invitation is a limited permission to join
Bind invitation tokens to a workspace, email address, role, and expiry.
Verification proves control of an email address
Explain purpose-specific tokens, expiry, and what verification does not establish.
Password reset creates a temporary credential
Understand reset tokens, generic responses, single use, and session revocation.
Isolation applies beyond ordinary routes
Find tenant risks in idempotency records, workers, sockets, logs, and caches.