Hacker News new | ask | show | jobs
by jagged-chisel 1535 days ago
But that's the difference between authentication and authorization - sure, you've logged in, and we can verify that, but now we need to know if you're permitted to do what you're trying to do. And yes, authorization will then have awareness of some amount of application/business logic.