From storing passwords, sessions and cookies, and CSRF, through email verification, social login (OAuth 2.0), plans and roles, rate limiting and two-factor authentication, all the way to audit logs and account deletion. Across 30 lessons you'll get to the point where you can build a membership site's login from end to end yourself. All code and test results were actually run against Django 6.1.
The 30 lessons are split into 6 chapters. We recommend working through them in order starting from Chapter 1, but feel free to skim just the parts you're curious about. * Django can't run in the browser, so try it in a virtual environment with Django, pytest-django, and pyotp installed. Examples that only need the standard library, like OAuth's state or rate limiting, can run right there in the browser. This course assumes you've taken the Django course.
Store passwords as hashes, keep login state with sessions and cookies, and reject spoofed POSTs with a CSRF token — confirm the foundations of authentication using Django's built-in features. We finish by seeing that login and logout really just mean recording and clearing a user ID in the session.
Send a confirmation email at signup, verify the address with a token link, and build password-free login codes and resets. We finish by rejecting weak passwords before signup and covering SMTP along with SPF, DKIM, and DMARC so your emails don't land in spam.
Break down the OAuth 2.0 authorization code flow behind "Sign in with Google" into the authorization URL, state, callback, and token exchange, and confirm each step. Cover key handling and account linking for each provider, then finish with why you should hand this off to django-allauth in production.
Attach a one-to-one Profile to User to hold plan and role, and separate out who's allowed to do what. Build the logic that shows full content only to paying members and controls the free preview, and finish by making sure no login-required page slips through unprotected.
Curb abuse with rate limiting, stop brute force with a lockout after repeated failures, and prepare for a leaked password with TOTP two-factor authentication. We finish with the mechanism that rotates the session ID on every login, and managing keys like SECRET_KEY through environment variables.
Triage "I can't log in" reports by cause, backed by an audit log that records who did what and when. We close out all 30 lessons by designing what account deletion erases and what it anonymizes and keeps.
Once you finish all 30 lessons, move on to Stripe Payments and Subscriptions, where you'll connect billing to the login you built. All courses unlock with a membership.