CHAPTER 11 · Security, Auth, and Multi-Tenancy · 1 / 9
The three questions
Every secured request must answer three questions in order:
- Authentication: who are you? Establish identity from a credential (session token, API key).
- Authorization: what may you touch? Given the identity, decide whether this specific action on this specific resource is allowed.
- Isolation: can tenants reach each other's data? Ensure that, by construction, one user's data can't leak to another.
Treat these as distinct. Many breaches come from conflating them: authenticating a user and then assuming they're authorized for whatever they asked for.