Deesha Tech Academy
Menu
WorkshopRuns on requestJavaScript & webAuthenticationOAuthWeb securityCORSXSSCSRF

Secure the Frontend — Authentication & Web Security Lab

Two hands-on days connecting a frontend to secured APIs without creating new problems — the OAuth login flow end to end, tokens handled honestly, protected routes and interceptors, then the browser's own battles: CORS, XSS, CSRF and roles enforced, not hidden.

Designed for

  • Frontend developers who copied a login flow and hope it is right
  • React and Angular developers connecting to secured APIs for the first time
  • Teams whose token lives in localStorage because a tutorial said so
  • Anyone who has "fixed" CORS with a wildcard and a sigh
Fee
₹2,700
Duration
2 days · 16 hours
Each day
09:00 – 17:00
Mode
Offline / Online
Request a schedule

The 2 days, hour by hour

10 hands-on sessions — every one ends in a thing

Day 1

09:00 – 17:00

Get authentication right

5 sessions

09:00 – 10:15

See the whole login flow before writing any of it

authentication vs authorisation, OAuth and OIDC in browser terms, the actors

Takeaway The full login dance drawn actor by actor — browser, app, provider, API — until no arrow on the diagram is a mystery.

10:30 – 11:45

Handle tokens and cookies honestly

access and refresh tokens, storage trade-offs, where tokens must never live

Takeaway A token stolen live from localStorage by one line of injected script — and the storage design that makes the same theft fail.

12:00 – 13:00

Protect the routes

route guards, redirects that return you, deep links after login

Takeaway Protected pages that survive refresh, deep links and the back button — the three ways tutorial guards usually break.

14:00 – 15:15

Wire the API layer

interceptors, transparent refresh, handling 401 vs 403

Takeaway An API layer that attaches tokens, refreshes them mid-session and retires them on failure — with no component ever touching one.

15:30 – 17:00

Log out like you mean it

ending sessions properly, multi-tab behaviour, expired sessions mid-form

Takeaway Logout that actually ends the session — proved across two tabs, and a mid-form expiry handled without losing the user's work.

Day 2

09:00 – 17:00

Hold the browser boundary

5 sessions

09:00 – 10:15

Understand CORS once and for all

what CORS protects, preflight requests, fixing it properly

Takeaway The CORS error read as the browser protecting someone — then fixed at the API with intent, not with a wildcard.

10:30 – 11:45

Meet XSS, the attack that owns your users

injection sinks, framework escaping and its escape hatches, CSP basics

Takeaway A working XSS attack built against the lab app — then killed twice, once by escaping and once by policy.

12:00 – 13:00

Close the cookie attacks

CSRF and when it applies, SameSite cookies, clickjacking and frames

Takeaway A CSRF attack that works against the naive setup and fails against yours — the cookie flags doing exactly what they claim.

14:00 – 15:15

Enforce roles, don't just hide buttons

permissions in the UI, display vs enforcement, roles from token claims

Takeaway The hidden admin button pressed anyway via the console — and the API refusing, because enforcement never lived in the UI.

15:30 – 17:00

Attack your own app and defend it

the attack checklist, fixing what lands, security review

Takeaway Your application attacked with the day's whole toolkit and surviving — with a written checklist you will run on every future frontend.

By the end of day 2, you are holding

Your frontend authenticating against a secured API the right way — OAuth/OIDC flow understood actor by actor, tokens handled and refreshed without localStorage folklore, routes protected, roles enforced rather than hidden — and the same app surviving the XSS and CSRF attacks you launched at it yourself.

Request a schedule

Secure the Frontend — Authentication & Web Security Lab

Runs on request, for individuals and for teams.

How will you join?

Laptop ready with the prerequisites?

Opens WhatsApp with a message naming this workshop. We confirm your seat and payment by reply — this website stores nothing.

More SkillLabs

One weekend, one capability

Browse the SkillLabs catalogue

Agent Builder Lab

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

AI App Engineering Lab

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Ground the Model — RAG Engineering Lab

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Agents in the Wild — Production Agent Lab

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Break It Before Users Do — AI Reliability Lab

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Give Your Agent Hands — MCP Tooling Lab

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Docker & Kubernetes for Developers

₹2,700 · 2 days · 16 hours

Next: 19 Sept

See the plan

Git, GitHub and GitHub Actions for Developers

₹2,700 · 2 days · 16 hours

Next: 22 Aug

See the plan

Ship It on AWS — Cloud Deployment for Developers

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

SQL for Application Developers

₹2,700 · 2 days · 16 hours

Next: 29 Aug

See the plan

Events in Motion — Kafka & Messaging for Java Developers

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Linux Command Line Essentials

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Logging & Monitoring for Production

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Performance & Production Readiness

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Redis & Caching for Java Services

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Test It Before You Ship It — Java API Testing Lab

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Test the User Journey — Frontend Testing Lab

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

TypeScript for Application Developers

₹2,700 · 2 days · 16 hours

Runs on request

See the plan

Who runs it

Practitioners, in the room with you

All trainers and mentors

Each workshop names its trainer before you book.

  • Vishal Shah

    Vishal Shah

    Founder & Principal Trainer

    Two decades building and teaching commerce, banking and cloud platforms — still writing code

    • Java & Spring Boot microservices
    • TypeScript, React, Angular & Next.js
    • Composable commerce (commercetools)
    Full profile →
  • Shrenik Shah

    Shrenik Shah

    Principal Trainer

    Cloud and AI architect who has upskilled over 5,000 engineers in Java, React, Python and cloud

    • Python — Django, Flask, GenAI & agentic workflows
    • Java & Spring Boot
    • React & Angular, micro-frontend architecture
    Full profile →

Running this for a team?

We deliver SkillLabs on site for institutions and engineering teams.

Talk to Deesha

₹2,700

2 days · 16 hours

Request a schedule