Lesson 1.24mIntermediate12.6k students

Authentication versus authorization

Authentication is who you are; authorization is what you may do. Broken access control is consistently the most common serious finding.

This lesson sits in Thinking About Threats, part of Practical Web Security. It assumes what came before it and leads directly into the next lesson in the module.

In this lesson you will

  • Separate identity from permission checks
  • Enforce authorization on the server, every time
  • Catch insecure direct object references

Pro tip

Every authorization check must happen on the server. A hidden button is not a permission.

Resources