Identity: Authentication, Authorization & OIDC Map
Authentication versus authorization, OAuth2 enough-to-use, OIDC, browser-to-Backend identity flow
Khóa Keycloak/OIDC/JWT/SSO/RBAC và Backend authorization boundary.
Đọc và bookmark được phép; mọi mutation vẫn bị khóa server-side cho đến khi week trước PASS.
PASS ≥ 75%
learner artifacts
Authentication versus authorization, OAuth2 enough-to-use, OIDC, browser-to-Backend identity flow
Keycloak realm/client/users/roles model and four-role DX-Lab demo setup
Authorization Code flow, PKCE, state/nonce concepts, callback, SSO and browser integration awareness
JWT header/payload/signature, sub/iss/aud/azp/exp/roles, JWKS and decode versus validate
Role claims, mapper, user assignment, Backend guard and 401/403/200 access matrix
Evidence-first 401/403/expiry/issuer/audience/role troubleshooting protocol
Keycloak realm export/import, persistence, secret protection, redirect review and reproducible identity setup