You should check out the owasp project at - http://www.owasp.org/index

Another good place to check would be the http://www.sans.org reading room or the http://www.securityfocus.com/ website. All three of these have papers on web application security, authentication, etc. secfocus has a good paper on testing your web application authentication scheme.