Identity and security
Authorization
Authorization decides whether a caller may perform a particular action on a particular resource. It uses rules such as ownership, role or purchased access. The trusted server or database enforces those rules; hiding a button only changes the interface.
You might see: AuthZ, access control, permissions
In a real project
Two people are signed in, but each may edit only their own reading list. Before saving a change, the server checks the caller against the list's owner instead of trusting an owner ID submitted by the browser.
A common mistake
Checking permission only when a page opens. Direct API requests and later changes still need their own checks, including which account owns the specific resource.
Put it into practice
These lessons open through your account. Your kit determines which are available.
Go to the source
Sources checked .