Identity and authorizationCHAPTER 08
PART B / Identity and authorization
Step 124 of 252
CHAPTER 08GUIDED READING

Identity and authorization

Enforce identity, ownership, and trust boundaries beyond the interface.

Enforce access where the protected action happens

Hiding another user’s Edit button does not stop a direct HTTP request. A saved URL can also cause the server to connect somewhere the user could not reach directly. Follow both the person’s permission and the service’s network privileges.

Begin with ownership checks in a local API, then extend to tenant boundaries, private links, and outbound fetches. Keep demonstration identity headers separate from production authentication. State the protected resource and action before selecting an AWS permission.

Parts group related chapters. Each lesson has a chapter.lesson address, such as 4.07. Open a title below, or use Next to follow the reading sequence. Within a lesson, On this page lists its sections.

  1. 8.01
  2. 8.02
  3. 8.03
  4. 8.04