Authentication versus authorization comparison showing identity verification and access control mechanisms
Security 8 min read

Authentication vs Authorization: What Each One Controls

Authentication verifies who someone is. Authorization determines what they can do. Conflating the two creates security gaps. Authentication answers "Are you who you claim to be?" Authorization answers "Are you allowed to do this?"

Authentication: Proving identity

Authentication verifies that users are who they claim to be. Common authentication methods include passwords, multi-factor authentication (MFA), OAuth, and API keys.

Password authentication

Password-based authentication requires a username and password. Passwords must be hashed using bcrypt, Argon2, or scrypt. Never store plaintext passwords. Hash functions designed for speed (MD5, SHA-1) are unsuitable for password storage.

// Example: bcrypt password hashing
const bcrypt = require('bcrypt');
const saltRounds = 10;

async function hashPassword(password) {
  return await bcrypt.hash(password, saltRounds);
}

async function verifyPassword(password, hash) {
  return await bcrypt.compare(password, hash);
}

Multi-factor authentication

MFA requires a second factor beyond passwords: something users have (phone, hardware token) or something users are (biometric). MFA significantly reduces account compromise risk.

Session tokens and JWTs

After authentication, applications issue tokens to maintain sessions. Session tokens are opaque identifiers stored server-side. JSON Web Tokens (JWTs) are self-contained and include claims about the user.

Session tokens require server-side storage but allow instant revocation. JWTs are stateless but cannot be revoked until expiration unless additional infrastructure is added.

Authorization: Controlling access

Authorization determines what authenticated users can access or modify. Authorization happens after authentication.

Role-based access control (RBAC)

RBAC assigns permissions to roles, and roles to users. For example, an "admin" role might have permissions to delete records, while a "viewer" role only reads data.

// Example: role check
function canDeletePost(user, post) {
  if (user.role === 'admin') return true;
  if (user.role === 'author' && post.authorId === user.id) return true;
  return false;
}

Attribute-based access control (ABAC)

ABAC evaluates policies based on user attributes, resource attributes, and context. ABAC is more flexible than RBAC but more complex to implement.

Resource ownership

Users should only access resources they own or are granted access to. Verify ownership at the authorization layer before allowing access:

// Example: ownership check
async function getDocument(userId, docId) {
  const doc = await db.documents.findById(docId);
  if (!doc) throw new NotFoundError();
  if (doc.ownerId !== userId) throw new ForbiddenError();
  return doc;
}

Common authentication and authorization mistakes

Assuming authentication implies authorization

Being authenticated does not mean users can access everything. Applications must check authorization separately for every action.

Client-side authorization checks

Client-side checks (hiding UI elements) improve user experience but do not enforce security. Authorization must be enforced server-side. Attackers bypass client-side restrictions trivially.

Insufficient token validation

JWTs must be validated on every request: signature verification, expiration, issuer, and audience. Skipping validation allows attackers to forge tokens.

Over-privileged roles

Assigning excessive permissions to default roles violates least privilege. Grant only the permissions required for a user's responsibilities.

Implementing authentication and authorization correctly

Separate concerns

Authentication and authorization are distinct responsibilities. Authentication middleware verifies identity. Authorization logic checks permissions before executing actions.

Centralize authorization logic

Avoid duplicating authorization checks across controllers. Centralize permission logic in reusable functions or authorization libraries.

Audit authentication and authorization events

Log authentication attempts, failures, and authorization denials. Logs detect attacks and support incident investigation.

Authentication and authorization are separate

Authentication verifies identity. Authorization controls access. Both are required for secure applications. Verify identity once, check permissions always. For broader security context, see Security-First API Design.


Published by the DSSS Engineering Team. For corrections or topic requests, use the contact page.