Week 3 operating page

Human / Identity

Khóa Keycloak/OIDC/JWT/SSO/RBAC và Backend authorization boundary.

Weekly review
AVAILABLE TO READ · LOCKED FOR PASS

Đọc và bookmark được phép; mọi mutation vẫn bị khóa server-side cho đến khi week trước PASS.

Missions
0/7
Weekly quiz
0%

PASS ≥ 75%

Evidence
0

learner artifacts

Boss Fight
OPEN
Open incident

Missions

MISSION 01 · Identity

Identity: Authentication, Authorization & OIDC Map

Authentication versus authorization, OAuth2 enough-to-use, OIDC, browser-to-Backend identity flow

NOT STARTEDOpen
MISSION 02 · Keycloak

Keycloak Realm, Client, Users & Roles

Keycloak realm/client/users/roles model and four-role DX-Lab demo setup

NOT STARTEDOpen
MISSION 03 · OIDC Flow

Authorization Code + PKCE & SSO

Authorization Code flow, PKCE, state/nonce concepts, callback, SSO and browser integration awareness

NOT STARTEDOpen
MISSION 04 · JWT

JWT Claims, JWKS & Backend Validation

JWT header/payload/signature, sub/iss/aud/azp/exp/roles, JWKS and decode versus validate

NOT STARTEDOpen
MISSION 05 · Authorization

RBAC: Roles, Claims, Mappers & Backend Guard

Role claims, mapper, user assignment, Backend guard and 401/403/200 access matrix

NOT STARTEDOpen
MISSION 06 · Troubleshooting

Identity Incident Triage: 401, 403 & Expiry

Evidence-first 401/403/expiry/issuer/audience/role troubleshooting protocol

NOT STARTEDOpen
MISSION 07 · Identity Operations

Realm Export/Import, Security Review & Reproducibility

Keycloak realm export/import, persistence, secret protection, redirect review and reproducible identity setup

NOT STARTEDOpen