Skip to catalogue

67

authn vs authz

also authentication vs authorization

Authn is who you are. Authz is what you may do. Logging in is not permission.

What is authn vs authz?

Authentication proves identity: password, passkey, session. Authorization decides an action on a resource: this user may edit this row. They fail differently and belong in different checks.

Why does authn vs authz matter when vibe coding?

Models add login and stop. Every route then trusts “any logged-in user.” That is how one customer reads another’s invoices. Say both words.

How do you do authn vs authz?

Every mutating route: identify the caller, then authorize the specific object. Test both a stranger and a logged-in stranger. 401 means not identified. 403 means identified and refused.

How do you ask a model for authn vs authz?

Separate authn and authz. 401 if there is no session. 403 if the session may not touch this (object). Do not treat “logged in” as permission.

What goes wrong with authn vs authz?

Hiding the button and leaving the route open. The UI is not the server.

adjacent