Lesson 3.35mIntermediate7.8k students
MFA and delegated authentication
A second factor defeats stolen passwords. OAuth and OIDC hand identity to a provider — useful, and only if you validate what comes back.
This lesson sits in Authentication Done Right, part of Practical Web Security. It assumes what came before it and leads directly into the next lesson in the module.
In this lesson you will
- Add a second factor without wrecking usability
- Distinguish OAuth authorization from OIDC identity
- Validate tokens and claims on every request
Resources
Your notes for this lesson will appear here.