Secure the Frontend — Authentication & Web Security Lab
Two hands-on days connecting a frontend to secured APIs without creating new problems — the OAuth login flow end to end, tokens handled honestly, protected routes and interceptors, then the browser's own battles: CORS, XSS, CSRF and roles enforced, not hidden.
Designed for
- Frontend developers who copied a login flow and hope it is right
- React and Angular developers connecting to secured APIs for the first time
- Teams whose token lives in localStorage because a tutorial said so
- Anyone who has "fixed" CORS with a wildcard and a sigh
- Fee
- ₹2,700
- Duration
- 2 days · 16 hours
- Each day
- 09:00 – 17:00
- Mode
- Offline / Online
The 2 days, hour by hour
10 hands-on sessions — every one ends in a thing
Day 1
09:00 – 17:00Get authentication right
5 sessions09:00 – 10:15
See the whole login flow before writing any of it
authentication vs authorisation, OAuth and OIDC in browser terms, the actors
Takeaway The full login dance drawn actor by actor — browser, app, provider, API — until no arrow on the diagram is a mystery.
10:30 – 11:45
Handle tokens and cookies honestly
access and refresh tokens, storage trade-offs, where tokens must never live
Takeaway A token stolen live from localStorage by one line of injected script — and the storage design that makes the same theft fail.
12:00 – 13:00
Protect the routes
route guards, redirects that return you, deep links after login
Takeaway Protected pages that survive refresh, deep links and the back button — the three ways tutorial guards usually break.
14:00 – 15:15
Wire the API layer
interceptors, transparent refresh, handling 401 vs 403
Takeaway An API layer that attaches tokens, refreshes them mid-session and retires them on failure — with no component ever touching one.
15:30 – 17:00
Log out like you mean it
ending sessions properly, multi-tab behaviour, expired sessions mid-form
Takeaway Logout that actually ends the session — proved across two tabs, and a mid-form expiry handled without losing the user's work.
Day 2
09:00 – 17:00Hold the browser boundary
5 sessions09:00 – 10:15
Understand CORS once and for all
what CORS protects, preflight requests, fixing it properly
Takeaway The CORS error read as the browser protecting someone — then fixed at the API with intent, not with a wildcard.
10:30 – 11:45
Meet XSS, the attack that owns your users
injection sinks, framework escaping and its escape hatches, CSP basics
Takeaway A working XSS attack built against the lab app — then killed twice, once by escaping and once by policy.
12:00 – 13:00
Close the cookie attacks
CSRF and when it applies, SameSite cookies, clickjacking and frames
Takeaway A CSRF attack that works against the naive setup and fails against yours — the cookie flags doing exactly what they claim.
14:00 – 15:15
Enforce roles, don't just hide buttons
permissions in the UI, display vs enforcement, roles from token claims
Takeaway The hidden admin button pressed anyway via the console — and the API refusing, because enforcement never lived in the UI.
15:30 – 17:00
Attack your own app and defend it
the attack checklist, fixing what lands, security review
Takeaway Your application attacked with the day's whole toolkit and surviving — with a written checklist you will run on every future frontend.
By the end of day 2, you are holding
Your frontend authenticating against a secured API the right way — OAuth/OIDC flow understood actor by actor, tokens handled and refreshed without localStorage folklore, routes protected, roles enforced rather than hidden — and the same app surviving the XSS and CSRF attacks you launched at it yourself.
Request a schedule
Secure the Frontend — Authentication & Web Security Lab
Runs on request, for individuals and for teams.
More SkillLabs
One weekend, one capability
Agent Builder Lab
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
AI App Engineering Lab
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Ground the Model — RAG Engineering Lab
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Agents in the Wild — Production Agent Lab
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Break It Before Users Do — AI Reliability Lab
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Give Your Agent Hands — MCP Tooling Lab
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Docker & Kubernetes for Developers
₹2,700 · 2 days · 16 hours
Next: 19 Sept
See the plan
Git, GitHub and GitHub Actions for Developers
₹2,700 · 2 days · 16 hours
Next: 22 Aug
See the plan
Ship It on AWS — Cloud Deployment for Developers
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
SQL for Application Developers
₹2,700 · 2 days · 16 hours
Next: 29 Aug
See the plan
Events in Motion — Kafka & Messaging for Java Developers
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Linux Command Line Essentials
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Logging & Monitoring for Production
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Performance & Production Readiness
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Redis & Caching for Java Services
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Test It Before You Ship It — Java API Testing Lab
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Test the User Journey — Frontend Testing Lab
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
TypeScript for Application Developers
₹2,700 · 2 days · 16 hours
Runs on request
See the plan
Who runs it
Practitioners, in the room with you
All trainers and mentorsEach workshop names its trainer before you book.

Vishal Shah
Founder & Principal Trainer
Two decades building and teaching commerce, banking and cloud platforms — still writing code
- Java & Spring Boot microservices
- TypeScript, React, Angular & Next.js
- Composable commerce (commercetools)

Shrenik Shah
Principal Trainer
Cloud and AI architect who has upskilled over 5,000 engineers in Java, React, Python and cloud
- Python — Django, Flask, GenAI & agentic workflows
- Java & Spring Boot
- React & Angular, micro-frontend architecture
Running this for a team?
We deliver SkillLabs on site for institutions and engineering teams.
₹2,700
2 days · 16 hours