Authorization
- In Turkish
- Yetkilendirme
In short
Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
What is authorization?
Authorization answers the question what are you allowed to do? It happens after authentication: once the system knows who is making a request, it checks rules to decide whether that identity may view a page, edit a record, call an API, or perform an admin action. If the check fails, the server refuses with 403 Forbidden, or sometimes 404 Not Found to avoid revealing that the resource exists.
Common models include role-based access control (RBAC), where permissions are grouped into roles like viewer, editor, and admin; attribute-based access control (ABAC), where rules consider attributes such as department, time of day, or resource owner; and relationship-based models, where access follows links like the owner of a document or the members of a team. OAuth scopes are another form of authorization, limiting what a third-party app can do on a user's behalf.
A building analogy helps: your ID badge proves who you are, which is authentication, but the badge system decides which doors open for you, which is authorization. Just as every door checks the badge, every request must be checked on the server, because hiding a button in the user interface does nothing to stop someone from calling the API directly.
Broken access control is ranked as the top risk in the OWASP Top 10 list of web application security risks. A classic example is an insecure direct object reference (IDOR), where changing /invoices/123 to /invoices/124 shows someone else's invoice because the server never checked ownership. Defend against it by denying access by default, checking permissions on every request in one central place, granting the least privilege needed, and writing tests that try to reach other users' data.
At a glance
Key takeaways
- Authorization decides what an authenticated identity may do.
- It always happens after authentication.
- RBAC groups permissions into roles; ABAC uses attributes and context.
- Permission checks must run on the server for every request.
- Deny by default and grant only the least privilege needed.
Example
// Allow the request only if the user owns the invoice or is an admin
app.get("/invoices/:id", requireLogin, async (req, res) => {
const invoice = await db.invoices.findById(req.params.id);
if (!invoice) return res.sendStatus(404);
const isOwner = invoice.ownerId === req.user.id;
const isAdmin = req.user.roles.includes("admin");
if (!isOwner && !isAdmin) {
return res.sendStatus(403); // authenticated, but not allowed
}
res.json(invoice);
});Readers ask
What is the difference between authorization and authentication?
Authentication confirms who a user is, while authorization determines what that user is allowed to do. A system must authenticate a request first and then authorize it before returning data or making changes.
What is RBAC?
RBAC, or role-based access control, assigns permissions to roles such as viewer, editor, or admin, and then assigns roles to users. It is simple to manage but can become rigid when rules depend on ownership or context.
What is the difference between 401 and 403?
401 Unauthorized means the request is not authenticated, for example because the login token is missing or invalid. 403 Forbidden means the server knows who the user is, but that user does not have permission.
Often compared
See also
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- OAuthSecurity, p. 22OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
- JWTSecurity, p. 19A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- API KeySecurity, p. 1An API key is a unique secret string that identifies an application or project when it calls an API, used to control access, track usage, and apply rate limits.
- Zero TrustSecurity, p. 49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- MiddlewareBackend & APIs, p. 30Middleware is software that sits between two layers of a system, most often code that runs between an incoming request and the final response in a web server.
Spotted a mistake or something missing on this page?Suggest an edit