...
- OWASP Authentication Cheat Sheet
- OWASP Forgot Password Cheat Sheet
- OWASP Session Management Cheat Sheet
- ESAPI Authenticator API and Tutorial
- ESAPI User API
- OWASP Forgot Password Cheat Sheet
- OWASP Development Guide: Chapter on Authentication
- OWASP Testing Guide: Chapter on Authentication
- Content Security Policy
- SANS/CWE CWE Entry 287 on Improper Authentication
- https://www.owasp.org/index.php/Codereview-Session-Management
- Reviewing Code for Session Integrity Issues
- Testing Session Management