Authentication on the Web (Sessions, Cookies, JWT, localStorage, and more)

Поділитися
Вставка
  • Опубліковано 28 лис 2024

КОМЕНТАРІ • 367

  • @agustinbs
    @agustinbs 5 років тому +511

    Best video on web auth that has ever been produce by the mankind. Period.

    • @BlokeBritish
      @BlokeBritish 3 роки тому +3

      produced by mankind but seems more like a machine just reading some text

    • @benedictsincere7366
      @benedictsincere7366 3 роки тому

      i guess im asking randomly but does someone know of a trick to get back into an Instagram account..?
      I was dumb forgot my password. I love any tips you can give me.

    • @JoonhwanLee
      @JoonhwanLee 2 роки тому +1

      2 years after, still best I think

    • @hellelo.5840
      @hellelo.5840 2 роки тому

      @@BlokeBritish actually its the best made by mankind, watch something else if you can't grasp it.

    • @BlokeBritish
      @BlokeBritish 2 роки тому +2

      @@hellelo.5840 first grasp what i said and then reply

  • @nitindaphale2008
    @nitindaphale2008 2 роки тому +2

    LIKE from INDIA. At least 15 videos, 10 articles, countless days I spent to understand (10%) about authentication techniques and you refreshed that knowledge in one shot!

  • @twiggeh3577
    @twiggeh3577 5 років тому +43

    this is still, a year later, the best resource that I've found on cookies and sessions! Chapeau

  • @medi7573
    @medi7573 6 років тому +149

    This video cant be better than it is now, dead simple, concise, strictly to the point,thank you so much for the GREAT content , keep up

    • @vabolshakov
      @vabolshakov 4 роки тому

      It can, if the author would tell about signed cookie based session

  • @MasonE81
    @MasonE81 5 років тому +120

    Dude. You are the man. The world needs more videos like this.

  • @TheLordoftheDarkness
    @TheLordoftheDarkness 8 місяців тому

    Finally, an explanation for web authentication for people who are not 5 years olds.

  • @blankblank1273
    @blankblank1273 2 роки тому +4

    Timestamps:
    Authentication: 0:16
    Session Auth/Flow: 1:24
    Session Auth/Features: 2:21
    Cookies: 4:10
    Cookies/Security: 5:50
    Cookies/Attributes: 7:14
    Cookies/Flags: 8:02
    CSRF: 8:47
    Tokens/Flow: 9:35
    Tokens/Features: 10:53
    JWT: 13:04
    JWT/Security: 16:23

  • @ArthurBurgan
    @ArthurBurgan 4 роки тому +30

    You're the man! It's incredible that we can consume this content for free in such a concise yet thoroughly delivered manner. A big thank you for the time you put in creating these videos and for sharing your knowledge with us!

  • @awabelmahe9700
    @awabelmahe9700 4 роки тому +4

    My goodness, man, not a single second wasted, just a non-stopping flow of information. Your videos are the best on the whole internet; concise, packed, and straight to the point. Thank you very much for what you're doing.

  • @girmamoges941
    @girmamoges941 3 роки тому +1

    No one had explained like this, it is exceptional and beyond any online presentation that mankind has ever encountered.
    Absolutely Phenomenal.
    If a grade has to be given to you, you deserve for five courses in a term with
    a grade of A+, A+, A+, A+ , A+ with flying colors, or in simple terms " very great distinction" .

  • @muj1003
    @muj1003 4 роки тому

    Best video on Auth. Deserves to be ranked higher by UA-cam ...

  • @karma_yogi_42
    @karma_yogi_42 4 роки тому

    i tried this same style to create a tutorial on php. i got pummeled down with down votes. people didt like it when i read out from a slide show. but you! you have done a great service to a lot of people. thank you!

  • @fb_a
    @fb_a 4 роки тому +10

    This video must be the *prerequisite* video for every web development/backend course out there.
    Thanks, man! crystal clear explanation!

  • @Oswee
    @Oswee 5 років тому +7

    I would LOVE to hear the same topic but in context of SPA & WebSockets authentication (distributed micro-service systems). This is the No.1 explanation in the whole UA-cam! You have a talent!

  • @fooked1
    @fooked1 4 роки тому

    This video summarizes hours of other videos and blog posts all over the Internet. Well done.

  • @BharCode09
    @BharCode09 4 роки тому

    Full, comprehensive, unbiased and objective unlike most of the speakers go gaga about 1000% STATELESS blah blah!
    Only REAL benefit I can think of jwt is, that it can mitigate DDSA, that a Front End service, which can reject the request with a just simple signature verification made on JWT, instead of every time going down to authenticate and then reject, as in the case of stateful.

  • @NikogBazza
    @NikogBazza 5 років тому +13

    This is the kinds of videos that I've been looking for like 3 years, Thank you so much Sr.

  • @ninadmanjaramkar9062
    @ninadmanjaramkar9062 4 роки тому +1

    This is the single most amazing piece of information on web auth on the entire internet. Wow.

  • @anubhavkumarrao3141
    @anubhavkumarrao3141 3 роки тому +1

    this is the best video on youtube for "Authentication" :)

  • @mrchi6611
    @mrchi6611 2 роки тому

    Wow. Talk about clarity.... I appreciate the effort. Your content is GOLD

  • @JimLloyd1
    @JimLloyd1 4 роки тому +1

    Nicely done. Clear and concise. One tiny quibble: The word "opaque" should be pronounced as "oh-pake", not as "oh-pack". It is a word borrowed from optics, where it means non-transparent. One might say that a one-way mirror is transparent on one side and opaque on the other.

  • @abdisamadkhalif4283
    @abdisamadkhalif4283 5 років тому +1

    Authentication = login + password (who you are).
    Authorization = permissions (what you are allowed to do).
    Nice video!

  • @spencerwilson-softwaredeve6384

    Hey I know this is an old video, but this video is what secured these concepts in my head. Every second of the video is high quality information with very little noise. Thanks!

  • @tales4604
    @tales4604 4 роки тому

    Authentication suddenly became easy. Thanks a lot, sir!

  • @seanlanghi9782
    @seanlanghi9782 3 роки тому

    Incredible quality and quantity of information here. I'm so grateful for this video. Thank you.
    (I'm a startup founder who's learning how to build a Web frontend!)

  • @eugenedumoga677
    @eugenedumoga677 3 роки тому

    Very very very very very very very very very very very very very very very..........on point. Sums everything on authentication simply! Great content!

  • @TechPoint56
    @TechPoint56 3 роки тому

    One tip is to watch this video after having some idea on this topics then it will clear all your doubts and be very useful, this I'm saying because a beginner might have difficulty registering all this as I had some time ago.

  • @abduraufsherkulov1393
    @abduraufsherkulov1393 4 роки тому

    Seriously, this channel is underrated!

  • @jitender83601
    @jitender83601 2 роки тому

    One of the best video on the JWT and session token management. Great work!

  • @123thebruno
    @123thebruno 3 роки тому +1

    the didactics of the video are excellent, congratulations .

  • @koraytugay
    @koraytugay 4 роки тому +2

    13:50 Authorization header is supposed to be used when making a request. It is not supposed to be returned by the server. The JWT is returned either in the body or as a cookie.

  • @raghualapati4839
    @raghualapati4839 4 роки тому

    cudos . This is THE BEST explination of session and token i have ever seen and in so much depth and details. Can't thank you enough guys. The best of the best..

  • @MrFallout86
    @MrFallout86 5 років тому +29

    one of the damn best video I've seen on the topic. Well done sir! And thank you!

  • @bholowasia
    @bholowasia 5 років тому +3

    Thanks for all your sessions!
    One thing on your note on horizontal scaling with session/cookies : once offloaded onto a distributed cache (say redis cluster with consistent hashing for shards) there shouldn't be a problem. If sessions are lost (in case we don't use redundant nodes to backup the session in redis-slave-nodes) - in most cases that should be acceptable. The user only needs to re-login.

  • @tylerlwsmith
    @tylerlwsmith 4 роки тому

    This is the most concise and informative resource I've ever seen covering web authentication. Thank you for making this.

  • @ringoaikocascade
    @ringoaikocascade 4 роки тому

    My grandfather bought this fruit juicer that you can just put in the whole fruit, with its skin and all, and squeezes every bit of it. This video reminded me of that hell of a machine.

  • @ExplorerSpace
    @ExplorerSpace 4 роки тому

    this is one of the super type of videos in the youtube

  • @rainerwahnsinn3262
    @rainerwahnsinn3262 4 роки тому +2

    13:47 You confuse request and response. "Authorization" is a request header, and you're showing it in a response. The token is sent in the body of the response, read out by the client, and then send in the "Authorization: Bearer " header in subsequent requests.

  • @t0khyo
    @t0khyo 11 місяців тому

    This video is my top pick for the year. Thanks for the awesome content - it really made a humongous difference for me!

  • @ashokrajur09
    @ashokrajur09 4 роки тому

    best presentation on authentication and its details.. thanks for your time in explaining it very clearly.. appreciate it.

  • @germanrocha6186
    @germanrocha6186 2 роки тому

    Excellent explanation. It covers everything you need to now about web auth. It saved me a lot of time and effort to learn it on my own. Very compact and clear. Thank you!!

  • @sbase20d
    @sbase20d 3 роки тому

    The very best on this topic, very clearly and precisely described, bravo!

  • @ghazini47
    @ghazini47 3 роки тому +1

    Thanks so much for the best video on JWT & Session based authentication.

  • @ziaahmad8738
    @ziaahmad8738 3 роки тому

    dude just thank u very much i was so confused but i am relieved now. Perfect.

  • @kevgits
    @kevgits 3 роки тому

    What a comprehensive and well-put-together vid! Thanks a lot!

  • @sanketgawande3667
    @sanketgawande3667 2 роки тому

    Thank you so much sir for this detailed session on client side web security and cookies session things .

  • @connormccafferty5288
    @connormccafferty5288 3 роки тому

    Extremely clear explanation.

  • @jaycelila6258
    @jaycelila6258 5 років тому +16

    hey you! solve most of the missed bridges in my brain. you deserve thumbs up

  • @tenminutetokyo2643
    @tenminutetokyo2643 4 роки тому

    Very straightforward and clear. Excellent. Thanks.

  • @fleskimiso
    @fleskimiso 4 роки тому

    Excellent video for overview of auth on the web.

  • @Aman-rm1hq
    @Aman-rm1hq 3 роки тому

    This is brilliant, you made so many concepts easier to understand in a simple video

  • @Sybrid203
    @Sybrid203 4 роки тому

    Wow man, I am amazed by how you simplified everything! Awesome video, made my understanding of all the auths concrete after I watched this video. You're amazing!

  • @ayushbajaj1965
    @ayushbajaj1965 3 роки тому

    This is Gold content. Hands down. Great.

  • @davidjiang7929
    @davidjiang7929 4 роки тому

    This information was really useful for me. I'm just starting webdev and wanted to learn more about how to keep the sessions secure. Thank you!

  • @vinnair77
    @vinnair77 4 роки тому

    One of the best videos on the topic.

  • @peloquin74
    @peloquin74 5 років тому

    Your video was a great teaching tool for my interns. You make the complicated simple. WELL DONE SIR!

  • @kaushikplays4676
    @kaushikplays4676 4 роки тому

    Best video one could get on Security. Underrated channel. Thanks!

  • @saikk5710
    @saikk5710 5 років тому +2

    I really enjoyed this video. You sir are a professional developer with very good presentation skills

  • @venkataswamy355
    @venkataswamy355 4 роки тому

    I spent days of time to understand the specified concepts but with this video opened my eyes.. Wonderful Work Sir! Please keep posting or refer if you already have anything related to OWASP Top 10 testing

  • @athisii_ekhe6167
    @athisii_ekhe6167 2 роки тому

    Beautifully explained and cleared my doubts. Thank you.

  • @vivianeb90
    @vivianeb90 3 роки тому

    It is puzzling but also interesting how your face is expressionless while your voice reads with some expression. Very fascinating.

  • @prasathj7436
    @prasathj7436 Рік тому

    Thanks for the excellent video. Clarified few doubts I had. Keep it going.

  • @ajeetworking
    @ajeetworking 4 роки тому

    Best auth tutorial I have watched. Thanks you

  • @argeelearner3978
    @argeelearner3978 6 років тому +2

    Wow!! Thanks bro for sharing. I see you put a lot of work into this video and it is really appreciated. I thought I can just watch this video but I see that i need to LEARN this video and it wont take me one sitting. Thanks again.

  • @prasundas4155
    @prasundas4155 4 роки тому

    while watching this video I was like damm this is what I needed. Thank you sir

  • @rinakanishi
    @rinakanishi 2 роки тому

    You're a lifesaver. I can't thank you enough!!

  • @clashoffans496
    @clashoffans496 4 роки тому

    Thanks a lot! This is the only well-explained content i found on the internet.

  • @rjk0128
    @rjk0128 7 місяців тому

    What a great video, clears many questions I had!

  • @nivellen1168
    @nivellen1168 3 роки тому

    Thank you very much for this video. I've been struggling with this for quite a while.

  • @anzo.p
    @anzo.p 3 роки тому

    Brilliant structure and presentation

  • @ClearlyCero
    @ClearlyCero 5 років тому +2

    The video is actual gold, good job mate

  • @reemachourey9462
    @reemachourey9462 3 роки тому

    Very nicely explained. Many thanks for sharing the notes.

  • @naafizrahman6538
    @naafizrahman6538 7 місяців тому

    BEST VIDEO EVER PRODUCED!
    ON AUTH

  • @baluhyajr.913
    @baluhyajr.913 2 роки тому

    I enjoyed very much this presentation.

  • @robertgardzinski6424
    @robertgardzinski6424 5 років тому

    Your video helped me a lot to understand authentication. You put it short and simple. Thank you! Guys like you makes the Internet a better place. :)

  • @shreyagarwal7113
    @shreyagarwal7113 3 роки тому

    Thanks for the effort you put to make it easy to understand. Thank you so much. Now I have more clarity about authentication. Keep making more such videos.

  • @wargaming67
    @wargaming67 4 роки тому

    This is exactly what I was looking for. Concise but informative explanation. Thank you!

  • @onieltoledo8019
    @onieltoledo8019 5 років тому +5

    Awesome video, thanks for this amazing presentation! Concise, to the point, with no jargon but you didn't miss any vital info. Many Thanks!

  • @idhasitha
    @idhasitha 5 років тому +1

    thank you very much for your time spend to create this, everything is here no need to watch any other video or blog regarding Authentication :)

  • @jmarioguedes
    @jmarioguedes 2 роки тому

    Excelent video! Hugs from Brazil.

  • @tedkollker3984
    @tedkollker3984 4 роки тому +1

    Very important information! Thank you very match! But one thing that can be improved: The changing of topics is without any notice, I am sure that if you will give a prominent header to a new topic, it will be even better

  • @stiffyBlicky
    @stiffyBlicky 4 роки тому

    Great videos. Straightforward, no bullshit. Thank you.

  • @engespress
    @engespress 3 роки тому

    Excellent information about two subjects that are difficult to understand.

  • @IPhonixI
    @IPhonixI 4 роки тому +2

    So how google
    Github. Twitter. Facebook. Instagram..etc...create websites and apis?
    They use something like JWT stareful? Which one do they use?

  • @Jay-zr8kx
    @Jay-zr8kx 4 роки тому

    This is the best content i have found

  • @zzubaidi
    @zzubaidi 4 роки тому +4

    one of the damn best video I've seen on the topic. Well done sir! And thank you

  • @laerciosv1
    @laerciosv1 3 роки тому

    Great job! Excellent presentation.

  • @khalidben9940
    @khalidben9940 4 роки тому +1

    so far the best video I encountered.Thank you for this amazing content.I am waiting for more like this

  • @IamKley
    @IamKley 6 років тому +6

    Looking forward to the node.js implementation videos!

    • @CodeRealm
      @CodeRealm  6 років тому +2

      Here you go ;-) ua-cam.com/video/OH6Z0dJ_Huk/v-deo.html

  • @surya_ch3809
    @surya_ch3809 4 роки тому

    Someone give this man a Medal..

  • @enfieldli9296
    @enfieldli9296 2 роки тому

    Matched by none, truly!

  • @omnipoten8
    @omnipoten8 4 роки тому

    The best explanation that I ever came across ! Thank you very much !

  • @ankuragrawal420
    @ankuragrawal420 3 роки тому

    Great content!! One correction , CSRF tokens are not sent as cookies. That would defeat the purpose of it as cookies can be forwarded from a malicious call. They are sent as separate headers.

  • @papanito4802
    @papanito4802 4 роки тому

    Agree with the rest here. Very very great video, good explanation.

  • @xpfe5zrm
    @xpfe5zrm 4 роки тому +2

    This is an amazing video. Very informative, and has little bias so that I can consider the trade offs for myself. Thank you for making this!

  • @JuanFrutos98
    @JuanFrutos98 3 роки тому

    Thanks, man. You really made everything clear for me now. I'm really thankful for your efforts.

  • @MrKeepItTrill
    @MrKeepItTrill 3 роки тому

    Amazing video, makes these concepts easy to understand. Thank you!

  • @anindian2055
    @anindian2055 3 роки тому

    This is PERFECT. Thank you for the wonderful content. Learned a lot as a penetration tester.

  • @TheAmritaSingh
    @TheAmritaSingh 2 роки тому

    Hi there, I have a requirement" to be able to trigger jenkins job remotely using JWT authentication" how can this be achieved

  • @Middollo
    @Middollo 9 місяців тому

    Exactly what ive been looking for. 🚀 thank you so much!