

0 / 2 embers
0 / 3000 xp
click for more info
Complete a lesson to start your streak
click for more info
Still calibrating
click for more info
Not enough gems
Cost: 6 gems
1: Authentication
incomplete
2: Stateless vs. Stateful Authentication
incomplete
3: What Are Sessions?
incomplete
4: What Are Cookies?
incomplete
5: Cookie Security
incomplete
6: Session Lifetime
incomplete
7: Password Resets
incomplete
8: Broken Password Reset Flow
incomplete
9: OAuth 2.0
incomplete
10: SAML and OIDC
incomplete
11: API Keys
incomplete
12: Reauthentication
incomplete
13: Authentication Misconceptions
incomplete
Back
ctrl+,
Next
ctrl+.
This lesson's interactive features are locked, please to keep using them
Not all actions deserve the same level of trust. Viewing your profile? Low risk. Changing your password? High risk.
Reauthentication asks a logged-in user for fresh proof of identity again before they perform a particularly sensitive action. Step-up authentication goes further by raising the session's assurance level, like requiring an additional or stronger factor.
Good candidates for reauth/step-up auth are:
Every reauthentication prompt adds user friction. Ask too often, and users will hate your app. Ask too little, and attackers with stolen sessions can cause damage.
Bearly Secure lets a logged-in user change their email address from the account page without re-entering their password.
Fix reauthentication before changing a user's email address.
With Bearly Secure still running, run and submit the CLI tests from the project root.