# Authorization

URL: https://softwaredictionary.org/terms/authorization
Category: Security
Last updated: 2026-09-30
In Turkish: Yetkilendirme

In short: Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.

## What is authorization?

Authorization answers the question what are you allowed to do? It happens after authentication: once the system knows who is making a request, it checks rules to decide whether that identity may view a page, edit a record, call an API, or perform an admin action. If the check fails, the server refuses with `403 Forbidden`, or sometimes `404 Not Found` to avoid revealing that the resource exists.

Common models include role-based access control (RBAC), where permissions are grouped into roles like viewer, editor, and admin; attribute-based access control (ABAC), where rules consider attributes such as department, time of day, or resource owner; and relationship-based models, where access follows links like the owner of a document or the members of a team. OAuth scopes are another form of authorization, limiting what a third-party app can do on a user's behalf.

A building analogy helps: your ID badge proves who you are, which is authentication, but the badge system decides which doors open for you, which is authorization. Just as every door checks the badge, every request must be checked on the server, because hiding a button in the user interface does nothing to stop someone from calling the API directly.

Broken access control is ranked as the top risk in the OWASP Top 10 list of web application security risks. A classic example is an insecure direct object reference (IDOR), where changing `/invoices/123` to `/invoices/124` shows someone else's invoice because the server never checked ownership. Defend against it by denying access by default, checking permissions on every request in one central place, granting the least privilege needed, and writing tests that try to reach other users' data.

## Key takeaways

- Authorization decides what an authenticated identity may do.
- It always happens after authentication.
- RBAC groups permissions into roles; ABAC uses attributes and context.
- Permission checks must run on the server for every request.
- Deny by default and grant only the least privilege needed.

## Example: Checking ownership before returning data (Express)

```javascript
// Allow the request only if the user owns the invoice or is an admin
app.get("/invoices/:id", requireLogin, async (req, res) => {
  const invoice = await db.invoices.findById(req.params.id);
  if (!invoice) return res.sendStatus(404);

  const isOwner = invoice.ownerId === req.user.id;
  const isAdmin = req.user.roles.includes("admin");
  if (!isOwner && !isAdmin) {
    return res.sendStatus(403); // authenticated, but not allowed
  }

  res.json(invoice);
});
```

## Frequently asked questions

**What is the difference between authorization and authentication?**

Authentication confirms who a user is, while authorization determines what that user is allowed to do. A system must authenticate a request first and then authorize it before returning data or making changes.

**What is RBAC?**

RBAC, or role-based access control, assigns permissions to roles such as viewer, editor, or admin, and then assigns roles to users. It is simple to manage but can become rigid when rules depend on ownership or context.

**What is the difference between 401 and 403?**

`401 Unauthorized` means the request is not authenticated, for example because the login token is missing or invalid. `403 Forbidden` means the server knows who the user is, but that user does not have permission.

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
