Skip to main content

Authorization

In Turkish
Yetkilendirme
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/authorization

In short

Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.

What is authorization?

Authorization answers the question what are you allowed to do? It happens after authentication: once the system knows who is making a request, it checks rules to decide whether that identity may view a page, edit a record, call an API, or perform an admin action. If the check fails, the server refuses with 403 Forbidden, or sometimes 404 Not Found to avoid revealing that the resource exists.

Common models include role-based access control (RBAC), where permissions are grouped into roles like viewer, editor, and admin; attribute-based access control (ABAC), where rules consider attributes such as department, time of day, or resource owner; and relationship-based models, where access follows links like the owner of a document or the members of a team. OAuth scopes are another form of authorization, limiting what a third-party app can do on a user's behalf.

A building analogy helps: your ID badge proves who you are, which is authentication, but the badge system decides which doors open for you, which is authorization. Just as every door checks the badge, every request must be checked on the server, because hiding a button in the user interface does nothing to stop someone from calling the API directly.

Broken access control is ranked as the top risk in the OWASP Top 10 list of web application security risks. A classic example is an insecure direct object reference (IDOR), where changing /invoices/123 to /invoices/124 shows someone else's invoice because the server never checked ownership. Defend against it by denying access by default, checking permissions on every request in one central place, granting the least privilege needed, and writing tests that try to reach other users' data.

At a glance

Authorization after login: Ada is signed in with the editor role. Her request to edit post 7 passes the rules and gets 200 OK; her request to delete it does not, because only admins may delete, so the server answers 403 Forbidden.Ada · editoredit post 7200 OKallowedAda · editordelete post 7403 Forbiddennot allowedRuleseditor: read, editadmin: read, edit, deletechecked on the server, every time
The server checks the rules on every request, starting from deny and granting only what each role needs.

Key takeaways

  • Authorization decides what an authenticated identity may do.
  • It always happens after authentication.
  • RBAC groups permissions into roles; ABAC uses attributes and context.
  • Permission checks must run on the server for every request.
  • Deny by default and grant only the least privilege needed.

Example

Checking ownership before returning data (Express)javascript
// Allow the request only if the user owns the invoice or is an admin
app.get("/invoices/:id", requireLogin, async (req, res) => {
  const invoice = await db.invoices.findById(req.params.id);
  if (!invoice) return res.sendStatus(404);

  const isOwner = invoice.ownerId === req.user.id;
  const isAdmin = req.user.roles.includes("admin");
  if (!isOwner && !isAdmin) {
    return res.sendStatus(403); // authenticated, but not allowed
  }

  res.json(invoice);
});

Readers ask

What is the difference between authorization and authentication?

Authentication confirms who a user is, while authorization determines what that user is allowed to do. A system must authenticate a request first and then authorize it before returning data or making changes.

What is RBAC?

RBAC, or role-based access control, assigns permissions to roles such as viewer, editor, or admin, and then assigns roles to users. It is simple to manage but can become rigid when rules depend on ownership or context.

What is the difference between 401 and 403?

401 Unauthorized means the request is not authenticated, for example because the login token is missing or invalid. 403 Forbidden means the server knows who the user is, but that user does not have permission.

Often compared

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings