DEV Community

Auth By Example
Auth By Example

Posted on

A reverse-proxy auth plugin is not application authorization

Quick check: call the same handler with a valid token for user A and a resource id belonging to user B. If the proxy plugin alone is what you relied on, that request often succeeds.

Edge auth proves who showed up. Application authorization decides what they may touch.

(Full disclosure, I work with Permit.io — useful when you want the PEP/PDP split spelled out beyond a proxy plugin.)

Top comments (0)