Level 3 · Advanced Secure & Real-Time¶
Goal: build an API that many users can share safely — with real authentication, fine-grained authorization, sensible cross-cutting behaviour (CORS, caching, rate limits), real-time features — and prove it with tests that exercise the security rules.
Three ideas carry this level:
- Authentication is not authorization. Knowing who someone is (lessons 1–2) tells you nothing about which records they may touch (lesson 3). Most real API breaches are the second kind.
- HTTP already has the answer.
WWW-Authenticate, CORS headers,ETag,If-Match,Retry-After, Server-Sent Events — use the protocol's mechanisms before inventing your own. - Per-process is a limitation, not a detail. Lifespan resources, in-memory caches, rate limiters and WebSocket rooms all live in one process. Know which of yours do, before Level 4 runs several.
Modules¶
- Password Hashing & the OAuth2 Password Flow — Argon2id with pwdlib, token endpoint, bearer dependency, the timing leak
- JWT Access Tokens & Refresh Tokens — claims, signature checks,
alg=none, rotation with reuse detection - Authorization: Scopes, Roles & Ownership —
SecurityandSecurityScopes, role factories, BOLA and how to prevent it - Middleware & CORS — ordering, pure ASGI middleware, GZip, TrustedHost, the wildcard-credentials trap
- Lifespan Events & Background Tasks — lifespan state, what background tasks can and can't promise
- WebSockets & Streaming Responses — JSON Lines, Server-Sent Events, an authenticated chat room
- Shaping the OpenAPI Schema — metadata, documented errors, operation IDs, a generated TypeScript client
- Async Tests & Isolated Test Databases —
AsyncClient, AnyIO, rollback isolation, real concurrency tests - Caching, ETags & Rate Limiting — 304s,
If-Matchoptimistic locking, a TTL cache, a token bucket - Project — A Multi-User Authenticated API — a bookmarks service with all of the above and 12 tests
What you need before starting¶
- Levels 1 and 2 of this course: dependencies, yield dependencies, async SQLAlchemy, settings and testing are used throughout.
- Security basics help: what hashing, signing and TLS are for. The Cybersecurity Mastery Path covers the background; this level focuses on implementing it in FastAPI.
- API design: for status-code and resource-design conventions beyond what's covered here, see the REST API Mastery Path.
- Install:
pip install "fastapi[standard]" "pwdlib[argon2]" pyjwt "sqlalchemy[asyncio]" aiosqlite pytest.
How the examples were checked¶
Every example ran on Python 3.14.7 with FastAPI 0.143.0, Starlette 1.7.0,
Uvicorn 0.54.0, pwdlib 0.3.1 (argon2-cffi 25.1.0), PyJWT 2.15.1,
SQLAlchemy 2.1.4, httpx 0.28.1 and AnyIO 4.15.1. Security behaviour — 401
vs 403, rejected alg=none tokens, refresh-token reuse detection, CORS responses — was
checked with the test client; WebSockets, streaming and background-task timing were
also checked against a real Uvicorn process with curl and the websockets client,
because the test client behaves differently in exactly those areas (lessons 5 and 6
show how). The TypeScript client in lesson 7 was generated with openapi-typescript
7.13.0 on Node 26.
What wasn't run
No Redis or other shared store was available, so distributed caching, distributed rate limiting and cross-process WebSocket broadcast are described, not demonstrated. Timing figures (Argon2's ~40 ms, the login-timing comparison) are from one laptop and will differ on yours; the differences they illustrate are the point.