Protect identities and access
Apply authentication, authorization, least privilege, and stronger sign-in.
- Distinguish proving an identity from deciding what it can do.
Authentication checks who or what is requesting access. Authorization decides which actions that identity may take. Least privilege grants only the permissions needed for a task and removes them when no longer needed. Multi-factor authentication combines different factor types, such as something you know and something you have; two passwords are still one factor type. Unique passwords and a password manager reduce the harm of reused credentials.
1permissions = {"reader": {"view"}, "editor": {"view", "change"}}
2role = "reader"
3action = "change"
4print("allowed" if action in permissions[role] else "denied")denied
Permission checks should be enforced on every relevant server request. Hiding a button does not prevent a user from calling an endpoint directly. Review privileged access and protect account recovery paths too.
Key takeaways
Authentication asks who; authorization asks what they may do.
MFA uses independent factor types.
Least privilege and server-side checks limit unauthorized access.
Lesson quiz
5 questions · pass with 4 correct · up to 50 XP
Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.
Questions about this lesson
Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.
Loading posts…