पाठ 1 / 25

Authentication Versus Authorization

Two separate questions, two separate checks.

AuthN and AuthZ

Authentication (AuthN) answers who is making this request? by verifying evidence such as a password, a passkey or a signed token. Authorization (AuthZ) answers is this identity allowed to do this action on this resource? They are separate steps: a perfectly authenticated user can still be forbidden from reading another customer's invoice. In HTTP terms, a missing or invalid credential usually earns 401 Unauthorized (despite the name, it means unauthenticated), while a valid identity without permission earns 403 Forbidden. Many real breaches come from APIs that authenticate correctly but forget to authorize each object.

Who are you, and what may you do?

Authentication proves identity; authorization decides what that identity is allowed to do. Every login system also faces predictable attacks.

Three ideas: authentication versus authorization, identity concepts, the threat model for login.
Figure 1.1 — Identify, authenticate, authorize.

Two middleware steps

Authenticate once, authorize per action (Express-style TypeScript sketch).

// 1. Authentication: establish req.user or reject with 401
function requireUser(req: Request, res: Response, next: NextFunction) {
  const user = sessionStore.lookup(req.cookies['__Host-sid']);
  if (!user) return res.status(401).json({ error: 'unauthenticated' });
  req.user = user;
  next();
}

// 2. Authorization: is THIS user allowed THIS action on THIS object?
app.get('/invoices/:id', requireUser, async (req, res) => {
  const invoice = await db.invoices.findById(req.params.id);
  if (!invoice || invoice.accountId !== req.user.accountId) {
    return res.status(404).end(); // do not reveal that it exists
  }
  res.json(invoice);
});

Passport control and boarding gate

Showing your passport at the airport proves who you are (authentication). Your boarding pass decides which plane you may board (authorization). Passing the first check does not let you onto every plane.

त्वरित जाँच: A logged-in user requests another tenant's record. Which check should stop them?

  • TLS certificate validation
  • Authentication
  • Authorization
  • Password hashing
Answer

Authorization — The user is already authenticated; the question is whether they may access that object.