Backend Security — Tập 10: Kiến trúc Bảo mật Thực tế
Đối tượng: Backend Engineer, Senior Backend Engineer, Tech Lead, Solution Architect, Software Architect. Mạch tư duy: Asset → Threat → Attack → Vulnerability → Defense → Trade-off → Production Best Practice. Chín tập trước xây dựng từ vựng và nguyên lý. Tập cuối này lắp ráp chúng vào các hệ thống thật. Với mỗi loại kiến trúc, ta hỏi: tài sản quan trọng nhất là gì, attacker nhắm vào đâu, và các nguyên lý (CIA, Least Privilege, Defense in Depth, Zero Trust, AuthN/AuthZ, token, TLS, secret) kết hợp thành luồng cụ thể ra sao. Trọng tâm là các luồng: Authentication, Authorization, Token Flow, Refresh Flow, API Gateway, Secret Management, Service-to-Service Authentication. ...