Contents

Security › Authentication & Authorization

Authentication vs Authorization

Authentication proves who you are; authorization decides what you may do.

Also known as: AuthN vs AuthZ

Authentication (AuthN) answers “who are you?” You check a password, a token, a fingerprint, and end up with an identity: this request is from user 42.

Authorization (AuthZ) answers “may you do this?” Given user 42, can they delete order 917? That depends on rules: they own it, they’re an admin, their plan allows it.

They’re separate steps, and authentication always comes first: you can’t decide what someone may do until you know who they are.

Why juniors should care

The classic bug is doing authentication and forgetting authorization:

@app.delete("/orders/{order_id}")
def delete_order(order_id: int, user = Depends(current_user)):  # authenticated ✓
    db.delete(Order, order_id)                                   # authorized? ✗

Any logged-in user can delete anyone’s order by changing the ID in the URL. This is called IDOR (Insecure Direct Object Reference) and is one of the most common real-world vulnerabilities. The fix is one check:

    order = db.get(Order, order_id)
    if order.owner_id != user.id:
        raise HTTPException(403)

Rule of thumb: every endpoint that touches a specific record should ask “does this user have access to this record?”, not just “is someone logged in?”