GCSE · Computer Science · AQA · Spec 8525

Authentication routines

Every login you have ever typed was judged by a few ordinary lines of code. Right username, wrong password? Let's watch which line keeps you out.

Computer Science · Robust programs

Watch a login refuse three attempts

Step through the code one line at a time. The variables on the right show exactly what the program knows at each moment.

Attempt 1 has the right username. Predict before you step: does the program let them in?

1 storedUser ← "kai07"
2 storedPass ← "tulip9"
3 attempts ← 0
4 loggedIn ← False
5 WHILE loggedIn = False AND attempts < 3
6 username ← INPUT
7 password ← INPUT
8 IF username = storedUser AND password = storedPass THEN
9 loggedIn ← True
10 OUTPUT "Welcome!"
11 ELSE
12 attempts ← attempts + 1
13 OUTPUT "Username or password not recognised"
14 ENDIF
15 ENDWHILE
16 IF loggedIn = False THEN
17 OUTPUT "Too many attempts. Locked out."
18 ENDIF

Variables

attempts=0loggedIn=Falsepassword=—username=—storedPass=tulip9storedUser=kai07

Output

 

Step 1: Set-up. The program already holds the right details: the stored values kai07 and tulip9. Nobody has tried yet, so attempts is 0 and loggedIn is False.

1 / 19

Use Next to move one line at a time. Pause at every IF and work out TRUE or FALSE yourself before you read the note.

Step 1 of 19: Set-up. The program already holds the right details: the stored values kai07 and tulip9. Nobody has tried yet, so attempts is 0 and loggedIn is False..

Watch out: Inside the IF, = is a question: "are these two values equal?" It gives TRUE or FALSE. The arrow ← is different: it stores a value in a variable.

Computer Science · Boolean logic

Four ways to try, one way in

Walk all four routes. How many of them end with access granted?

Username check → Password check

4 possible results of one login attempt.

On A user enters a username and a password. 2 branches to choose from.

Every attempt is checked twice: the username, then the password. Walk each route and see where it ends.

Watch out: Swap AND for OR and three of these four routes would lead in, including a stranger who guesses just the password.

Computer Science · Debugging

Why does this login allow a fourth try?

This routine should allow at most 3 attempts. Testing shows that a user who keeps getting it wrong is given 4. Which line is faulty?

A routine with one bug — which line goes wrong?

Computer Science · Algorithms

Trace table — dry run the code

Kai types the username kai07 and the password m00n. m00n is a real password, but it is not Kai's. Predict: in or out?

1users ← ["amir", "kai07", "zoe_b"]
2passwords ← ["k3ttle", "tulip9", "m00n"]
3username ← INPUT
4password ← INPUT
5granted ← False
6FOR i ← 0 TO 2
7 IF users[i] = username AND passwords[i] = password THEN
8 granted ← True
9 ENDIF
10ENDFOR
11IF granted = True THEN
12 OUTPUT "Access granted"
13ELSE
14 OUTPUT "Access refused"
15ENDIF
i
users[i]
passwords[i]
granted
Output
Press Start to run the first line.
·

Ready when you are — step through one line at a time.

Computer Science · Robust programs

Sensible data, or the right person?

Is each check validation or authentication?

Still to sort

Validation (0)

Checks the input is sensible or follows a rule.

Where the line is: Anyone can type data that passes validation. It says nothing about who they are.

Authentication (0)

Checks the user is who they claim to be.

Where the line is: Needs the user's details to match what is stored for them.

6 of 6 still to sort.

Programs make lots of checks. Sort each one, then read why it goes there.

Watch out: Do not sort by what the check looks at. Sort by the question it answers.

Computer Science · Your turn

Write your own login

A club's booking program stores the username "coach1" and the password "whistle". Write pseudo-code for an authentication routine that uses a REPEAT…UNTIL loop, gives the user up to 4 attempts, and outputs a lockout message if all 4 fail. Then state how this routine helps keep the booking program secure. [6 marks]

0 words · your answer stays on this page and is not sent anywhere.

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

What you need to know

  • Authentication confirms that a user is who they claim to be before the program lets them continue or access data.
  • A simple routine inputs a username and a password and compares both with stored (expected) values.
  • Access is granted only when the username AND the password both match; if either does not, access is refused and a message is output.
  • A WHILE or REPEAT loop lets the user try again, and a counter limits the attempts, locking the user out once the limit is reached.
  • Credentials can be stored in variables, or in lists where each password is at the same position as its username.
  • Validation checks data is sensible; authentication checks the user's identity.

The big picture

An authentication routine checks that a user is who they claim to be before letting them into a program or its data. It inputs a username and password, compares each with the stored value, and uses AND inside an IF so access is granted only when both match. A loop gives the user another try after a failure, and a counter locks them out once the limit is reached. This is different from validation, which only checks that data is sensible.

Key points

1Authentication is built from ordinary constructs: input, string comparison with =, AND, and IF…ELSE.
2TRUE AND FALSE is FALSE: one correct detail is never enough.
3String comparison is exact. Tulip9 and tulip9 are different strings.
4The counter goes up by 1 on each failure; the loop condition stops the loop when it reaches the limit.
5With stored lists, the password checked is the one at the same index as the username.
6Authentication routines help keep a program secure by keeping unauthorised users out of it and its data.

Worked example

Problem

Use the login routine from the top of the page (stored details kai07 and tulip9, a limit of 3 attempts). A user types kia07 and tulip9, then kai07 and tulip9. What does the program output, and what are attempts and loggedIn when it finishes?

⚠ Watch out

Thinking a correct username gets you halfway in. With AND, one match counts for nothing: TRUE AND FALSE is FALSE, so the user is refused exactly as if both were wrong.

🧠

Memory hook

Both or nothing, and count the fails. Username AND password must match, and the counter says when the tries run out.

✓

Check yourself

Stored details: ada and lamp22, with 3 attempts allowed. A user types ada and Lamp22 on their first go. Are they let in, and what happens to attempts?

Flashcards

(13)
What is authentication?
Confirming that a user is who they claim to be before the program lets them continue or access data.
What two inputs does a simple authentication routine ask for?
A username and a password.
What are the entered username and password compared with?
The stored (expected) values for that user.
In IF password = storedPass, what does = do?
It compares the two strings and gives TRUE or FALSE. It does not store anything.
Are Tulip9 and tulip9 equal strings?
No. The first characters differ (T and t), so the comparison is FALSE.
Why is AND used to combine the username and password checks?
AND is only TRUE when both checks are TRUE, so a user with just one correct detail is refused.
What would go wrong if OR joined the two checks?
A user with only one detail right, such as only the password, would be let in.
Which construct decides whether to grant or refuse access?
Selection: an IF…ELSE.
Which construct lets the user try again after a failed attempt?
Iteration: a WHILE or REPEAT loop.
What does the attempts counter do?
It goes up by 1 on each failed attempt, and the loop stops once it reaches the limit, locking the user out.
Credentials are stored in two lists. Which password is checked for the username typed?
The password at the same position (index) as that username.
What does validation check?
That input data is sensible or follows a rule, for example a range or length check.
Why do programs use authentication routines?
To stop unauthorised users getting into the program or its data.

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More AQA GCSE Computer Science topics

See the full AQA Computer Science curriculum →

How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 30 September 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.