Who is signed in, and what they may do.
WHAT AUTHENTICATION IS
Establishing who someone is.
WHAT AUTHORISATION IS
Deciding what they may do.
WHAT THE FRAMEWORK PROVIDES
Sign-in, registration, password reset and session handling A system for defining permissions
WHAT TO USE
The provided system, rather than writing your own.
WHY
Password hashing, session regeneration and token handling are all handled correctly.
WHAT TO DEFINE FOR AUTHORISATION
Policies describing who may do what to each kind of record.
WHAT TO CHECK
Every action against a record, before performing it.
WHY
Without it, changing an identifier in a request grants access to someone else's data.
THAT IS THE MOST COMMON SERIOUS FAULT IN CUSTOM APPLICATIONS
WHERE TO ENFORCE IT
In the application, not only by hiding interface elements.
WHAT TO ALSO IMPLEMENT
Rate limiting on sign-in A second authentication step, where warranted Session invalidation on password change
WHAT TO TEST
Attempting to access another user's record directly.