Free through lesson 3

Intro to Authentication & Membership Features

From storing passwords, sessions and cookies, and CSRF, through email verification, social login (OAuth 2.0), plans and roles, rate limiting and two-factor authentication, all the way to audit logs and account deletion. Across 30 lessons you'll get to the point where you can build a membership site's login from end to end yourself. All code and test results were actually run against Django 6.1.

Curriculum

The 30 lessons are split into 6 chapters. We recommend working through them in order starting from Chapter 1, but feel free to skim just the parts you're curious about. * Django can't run in the browser, so try it in a virtual environment with Django, pytest-django, and pyotp installed. Examples that only need the standard library, like OAuth's state or rate limiting, can run right there in the browser. This course assumes you've taken the Django course.

Chapter 1 — Fundamentals of Authentication (lessons 1–5)

Store passwords as hashes, keep login state with sessions and cookies, and reject spoofed POSTs with a CSRF token — confirm the foundations of authentication using Django's built-in features. We finish by seeing that login and logout really just mean recording and clearing a user ID in the session.

Chapter 2 — Email Verification and Login (lessons 6–11)

Send a confirmation email at signup, verify the address with a token link, and build password-free login codes and resets. We finish by rejecting weak passwords before signup and covering SMTP along with SPF, DKIM, and DMARC so your emails don't land in spam.

Chapter 3 — Social Login (lessons 12–18)

Break down the OAuth 2.0 authorization code flow behind "Sign in with Google" into the authorization URL, state, callback, and token exchange, and confirm each step. Cover key handling and account linking for each provider, then finish with why you should hand this off to django-allauth in production.

12

The OAuth 2.0 Authorization Code Flow

The OAuth 2.0 behind "Sign in with Google." How the flow connects authorization URL → consent → code → token exchange without ever handing your password to the app, and its URL parameters.

🔒 Basic
13

Prevent Login Hijacking with state

state is OAuth's easiest parameter to forget and its most dangerous one to skip. Generate an unguessable random value, save it to the session, and compare it in constant time at the callback.

🔒 Basic
14

Receive code and state at the Callback

The provider redirects back to your registered redirect_uri with code and state attached. Why you check state before using code, and the exact-match rule behind the common redirect_uri mismatch error.

🔒 Basic
15

Exchange the Authorization Code for a Token

Exchange the authorization code from the callback for an access token and id_token, server to server. Writing a test that injects the HTTP call, and why client_secret must never reach the browser.

🔒 Basic
16

Keys and Settings for Google, GitHub, LINE, and X

Collect each provider's authorization endpoint and scope into one table, and build all four authorization URLs with one function. Key points for each developer console, and never hardcoding keys.

🔒 Basic
17

Link a Social Account to a User

Social login only ever gives you the provider's uid. Make (provider, uid) unique and link it to your user to prevent duplicates. The callback's three branches, and why you don't auto-link by email.

🔒 Basic
18

Hand Social Login Off to django-allauth

django-allauth fully handles state verification, callback, token exchange, and account linking. How hard this is to build gap-free yourself, and which settings stay your job even after adopting it.

🔒 Basic

Chapter 4 — Storing Member State (lessons 19–23)

Attach a one-to-one Profile to User to hold plan and role, and separate out who's allowed to do what. Build the logic that shows full content only to paying members and controls the free preview, and finish by making sure no login-required page slips through unprotected.

Chapter 5 — Defending Against Attacks (lessons 24–27)

Curb abuse with rate limiting, stop brute force with a lockout after repeated failures, and prepare for a leaked password with TOTP two-factor authentication. We finish with the mechanism that rotates the session ID on every login, and managing keys like SECRET_KEY through environment variables.

Chapter 6 — Operations (lessons 28–30)

Triage "I can't log in" reports by cause, backed by an audit log that records who did what and when. We close out all 30 lessons by designing what account deletion erases and what it anonymizes and keeps.

Once you finish all 30 lessons, move on to Stripe Payments and Subscriptions, where you'll connect billing to the login you built. All courses unlock with a membership.