
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, and data engineering — plus mindset essays on confidence, routines, health, and sport psychology.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Sat, 15 Aug 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/세션/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/architecture/2026-08-15-guide-auth-and-authorization.en</guid>
    <title>The Complete Guide to Authentication and Authorization: Ten Misconceptions, Corrected From the Specs</title>
    <link>https://www.youngju.dev/blog/architecture/2026-08-15-guide-auth-and-authorization.en</link>
    <description>OAuth 2.0 is an authorization framework; OIDC is the authentication layer on top of it. This guide corrects the flows that fell out of the recommendations, the illusion of JWT validation, and the real trade-offs of token storage — using the text of RFC 6749, 9700, 7636, 7519, 8725, OIDC Core, and the OWASP cheat sheets. If the existing OAuth deep dive was about how it works, this one is about where it goes wrong.</description>
    <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>인증</category><category>인가</category><category>oauth</category><category>oidc</category><category>jwt</category><category>보안</category><category>세션</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/architecture/2026-08-15-guide-auth-and-authorization.ja</guid>
    <title>認証と認可 完全ガイド: 仕様原文で正す10の誤解</title>
    <link>https://www.youngju.dev/blog/architecture/2026-08-15-guide-auth-and-authorization.ja</link>
    <description>OAuth 2.0 は認可フレームワークであり、その上に認証を載せるのが OIDC です。推奨から外れたフロー、JWT 検証をめぐる錯覚、トークン保存場所のトレードオフを、RFC 6749・9700・7636・7519・8725、OIDC Core、OWASP チートシートの原文で整理します。既存の OAuth 詳解が「どう動くか」なら、この記事は「どこで間違えるか」です。</description>
    <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>인증</category><category>인가</category><category>oauth</category><category>oidc</category><category>jwt</category><category>보안</category><category>세션</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/architecture/2026-08-15-guide-auth-and-authorization</guid>
    <title>인증과 인가 완전 가이드: 스펙 원문으로 짚는 열 가지 오해</title>
    <link>https://www.youngju.dev/blog/architecture/2026-08-15-guide-auth-and-authorization</link>
    <description>OAuth 2.0은 인가 프레임워크이고 OIDC가 그 위에 인증을 얹습니다. 권장에서 빠진 플로우, JWT 검증에 대한 착각, 토큰 저장 위치의 교환 조건을 RFC 6749·9700·7636·7519·8725와 OIDC Core, OWASP 치트시트 원문으로 정리합니다. 기존 OAuth 심화 글이 &quot;어떻게 동작하는가&quot;였다면 이 글은 &quot;어디서 틀리는가&quot;입니다.</description>
    <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>인증</category><category>인가</category><category>oauth</category><category>oidc</category><category>jwt</category><category>보안</category><category>세션</category>
  </item>

    </channel>
  </rss>
