A reverse-proxy auth plugin is not application authorization
Quick check: call the same handler with a valid token for user A and a resource id belonging to user B. If the proxy plugin alone is what you relied on, that request often succeeds. Edge auth proves who showed up. Appli
Quick check: call the same handler with a valid token for user A and a resource id belonging to user B. If the proxy plugin alone is what you relied on, that request often succeeds.
Edge auth proves who showed up. Application authorization decides what they may touch.
(Full disclosure, I work with Permit.io β useful when you want the PEP/PDP split spelled out beyond a proxy plugin.)
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.