Knowledgebase

Authentication and Authorisation Print

  • phplaravel, password, permissions, guide, howto, solution, zillionkinghost, hosting
  • 0

Who is signed in, and what they may do.

WHAT AUTHENTICATION IS

Establishing who someone is.

WHAT AUTHORISATION IS

Deciding what they may do.

WHAT THE FRAMEWORK PROVIDES

Sign-in, registration, password reset and session handling A system for defining permissions

WHAT TO USE

The provided system, rather than writing your own.

WHY

Password hashing, session regeneration and token handling are all handled correctly.

WHAT TO DEFINE FOR AUTHORISATION

Policies describing who may do what to each kind of record.

WHAT TO CHECK

Every action against a record, before performing it.

WHY

Without it, changing an identifier in a request grants access to someone else's data.

THAT IS THE MOST COMMON SERIOUS FAULT IN CUSTOM APPLICATIONS

WHERE TO ENFORCE IT

In the application, not only by hiding interface elements.

WHAT TO ALSO IMPLEMENT

Rate limiting on sign-in A second authentication step, where warranted Session invalidation on password change

WHAT TO TEST

Attempting to access another user's record directly.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot