Building Software

Engineering Fundamentals for the Agent Era

Contents Section 8, Security

Authentication and Authorization

Mistakes to catch in review

  1. An endpoint that returns any record whose ID you put in the URL, because it checks that you are logged in but not that the record is yours.

  2. A password-reset or invite token that never expires and still works after it has been used once.

  3. Tokens accepted without verifying their signature, algorithm or expiry.

  4. Passwords stored with a fast hash or without a salt.

Proving who someone is and deciding what they are allowed to do, on every request and for every object.

Topics

Authentication
Passwords and password hashing, multi-factor authentication and passkeys.
Sessions and Tokens
Cookies, bearer tokens and signed tokens, and how to handle expiry and revocation.
Authorization Models
Roles, attributes and ownership, with permission checked on the server for every action.
Object-Level Authorization
Confirming the caller may access this specific record, a check endpoints often skip once login is confirmed.
Delegated Access
OAuth-style flows that let one system act for a user with limited, revocable scope.

You understand it when you can

  • List every check an endpoint must perform before returning a given object.
  • Explain how passwords should be stored and why fast hashes fail against offline attacks.
  • Test an application for broken object-level authorization by swapping record IDs between two accounts.

Drill

An agent built GET /api/invoices/:id, which checks for a valid session and then returns the invoice with that ID. Find how one customer reads another customer's invoices, and write the test that proves the fix works.

Start here

Watch

OAuth 2.0 and OpenID Connect (in plain English)

Nate Barbettini, 2018. 62-minute talk.

The clearest explanation of delegated access: scopes, authorization codes, access tokens, and how OpenID Connect adds identity on top of OAuth. Its implicit-flow advice is outdated; use authorization code with PKCE instead.

How Passkeys Work - Computerphile

Mike Pound, 2025. 19-minute explainer.

Explains the public-key challenge-response behind passkeys and why it resists phishing and server-side credential theft in ways passwords cannot.

Read

API Security in Action

Neil Madden, 2020.

Builds an API step by step and adds authentication, session cookies versus tokens, signed and encrypted tokens, OAuth, and capability-based authorization, including expiry and revocation.

Hacking APIs: Breaking Web Application Programming Interfaces

Corey Ball, 2022.

Teaches the attacker's side of BOLA and broken function-level authorization, including the two-account ID-swapping test the competencies ask for.

OAuth 2 in Action

Justin Richer and Antonio Sanso, 2017.

Builds client, authorization server and protected resource from scratch, so you see how delegated, scoped, revocable access actually works and where implementations go wrong.

Primary sources