Dev.to Security πŸ” Cybersecurity πŸ‘ 0

A reverse-proxy auth plugin is not application authorization

Quick check: call the same handler with a valid token for user A and a resource id belonging to user B. If the proxy plugin alone is what you relied on, that request often succeeds. Edge auth proves who showed up. Appli

Quick check: call the same handler with a valid token for user A and a resource id belonging to user B. If the proxy plugin alone is what you relied on, that request often succeeds.

Edge auth proves who showed up. Application authorization decides what they may touch.

(Full disclosure, I work with Permit.io β€” useful when you want the PEP/PDP split spelled out beyond a proxy plugin.)

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.