Security Boundaries: API Keys, Auth Concepts, and CORS
By the end of this module you can reason about API keys, authentication and CORS as boundaries - and explain why CORS is a browser rule, not a security control.
Units
- Unit 10.00: What an API key does and does not prove
- Unit 10.01: Where credentials belong, and where they leak
- Unit 10.02: Authorisation is not authentication
- Unit 10.03: CORS, and what it actually protects
- Unit 10.04: Rate limits and the state they need
