Authorization
also: authz, authorize, authorized, access control, permission check
Deciding what someone is allowed to do once you know who they are. For example, only admins can delete posts, and customers only see their own orders.
Enforcing permissions for an authenticated identity: which data it can read and which actions it can take. Implemented as role checks, ownership checks ("is this your order?") or database rules like Postgres row-level security. It must be enforced on the server, not just hidden in the interface.
Your hotel key card. Every guest has shown ID at the desk, but your card only opens your room and the gym, not anyone else's room.
Agents sometimes hide a button and call it done. Real authorization is checked on the server for every request. Knowing the difference lets you ask the question that prevents data leaks.
Any logged-in user can currently call DELETE /api/posts/:id. I'll add an authorization check so only the author or an admin can delete a post.
Check every endpoint that returns customer data. Confirm the server verifies the record belongs to the logged-in user, not just that someone is logged in.
Thinking hiding a button is enough. If the server doesn't check permissions, anyone can call the endpoint directly.