Hacker News new | ask | show | jobs
by mcluck 750 days ago
> To authenticate is to prove who you are. To authorize is to grant access.

We should be screaming this type of thing from the rooftops. I struggled so much with the difference until someone said something to this effect. AuthN = who you are, AuthZ = what can you do. People seem to get confused because certain classes of individuals have certain rights and think it's the "who" that's important and not the role