We're sorry but this app doesn't work properly without JavaScript enabled. Please enable it to continue.

Learn Web Security in Go

Harden a real Go web app with advanced authentication, and protection from injection, infrastructure, and operational security threats.

Also available in:

typescript

What you'll learn in this Go course

Learn everything you need to know about practical web security by patching a vulnerable Go, net/http, and SQLite application. You'll secure authentication and authorization, stop injection and browser attacks, protect sensitive data, improve infrastructure defenses, and prepare for denial-of-service attacks and incident response.

Chapter List

1
OWASP
Learn the OWASP Top 10 and how common web security risks shape secure application design.
2
Authentication
Learn how web apps verify users with sessions, cookies, password resets, OAuth, SAML, OIDC, and API keys.
3
Multi-Factor Authentication
Learn how MFA improves account security with hardware tokens, TOTP, passkeys, and recovery flows.
4
Authorization
Learn how to enforce access control with least privilege, RBAC, ABAC, IDOR defenses, and signed URLs.
5
Injection
Learn how injection attacks work and how to defend against SQL injection, unsafe archive extraction, prompt injection, and file upload risks.
6
Client-Side Security
Learn how to defend browser-facing apps against XSS, CSRF, clickjacking, unsafe CORS, and missing security headers.
7
Data Leaks
Learn how to prevent sensitive data exposure through safer API responses, error handling, and sanitized logs.
8
Infrastructure Security
Learn how to manage secrets, limit build and source leaks, defend against SSRF and redirects, and handle dependency risk.
9
Secure Transport
Learn how HTTPS, TLS, certificates, encryption, and signatures protect data in transit.
10
Secure Storage
Learn how to protect stored data with encryption, key management, password KDFs, database controls, and safe payment flows.
11
DDoS
Learn how to reduce abuse and availability risks with rate limits, throttling, queues, resource limits, bot detection, and CAPTCHA.
12
Incident Response
Learn how teams detect, triage, report, contain, and learn from security incidents.

Join 39 students in the Learn Web Security in Go course

Read reviews of their learning experiences

or view more reviews

Mediocrity doesn't cut it anymore

The only way to become a great developer is to write a lot of code

Avoid tutorial hell

by writing a ton of code

Stay motivated with

a game-like curriculum

Build portfolio projects

to prove your skills

Delve deeper

into foundational concepts

Learn flexibly online

without interrupting your life

For 1% the price of college

to minimize your financial risk

Frequently asked Questions

Got questions? We've got answers

Yes! It's free to create an account and start learning. You'll get all the immersive and interactive features for free for a few chapters. After that, if you still haven't paid for a membership, you'll be in read-only (content only) mode.