Authorization
In this chapter, we add authorization to the shop API: the server has verified who the caller is, and now it has to decide whether that caller is allowed to do what the request asks.
After reading this chapter, you should be able to:
- Distinguish authentication from authorization, and explain why hiding a control in the frontend does not enforce a permission
- Derive roles and permissions from requirements, and explain least privilege and deny by default
- Explain why a role check is not enough to decide access to a particular cart or order, and when a refusal should report the resource as not found
- Combine role, ownership, and resource state in a policy, choose the error response for each failing condition, and explain separation of duties
- Place authentication and the authorization checks in a layered application, and explain which checks a gateway can make
- Explain which requests a role removal affects and what a requirement on revocation has to specify