Establishing who someone is.
WHAT AUTHENTICATION IS
Establishing identity.
WHAT AUTHORISATION IS
Determining what they may do.
WHAT TO USE
Established libraries and framework facilities.
WHY
Password hashing, session handling and token issuance are easy to implement subtly wrong.
WHAT TO NEVER DO
Store passwords in a recoverable form Use general-purpose hashing for passwords Write your own scheme
WHAT TO USE FOR PASSWORDS
An algorithm designed for the purpose, which is deliberately slow.
WHAT SESSION APPROACHES EXIST
Server-side sessions, referenced by a cookie Tokens carried by the client
WHAT TO CONFIGURE ON COOKIES
Secure transmission only Inaccessible to scripts Restricted cross-site sending A sensible expiry
WHAT TO DO ON SIGN-IN
Regenerate the session identifier.
WHAT TO DO ON PASSWORD CHANGE
Invalidate other sessions.
WHAT TO IMPLEMENT
Rate limiting on authentication attempts A second factor, where warranted
WHAT TO CHECK ON EVERY PROTECTED ACTION
That the user is entitled to that specific record.