freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #31 of 45

authorization · what can you do

RestaVSThe 401 Bandit
Resta saysAuthorization answers "what are you allowed to do?" — enforced after authentication.

Once identity is known, authorization decides which actions and resources the caller may access. Common models: role-based (RBAC — admin vs member), attribute-based (ABAC — rules over attributes), and scopes (OAuth tokens granting specific permissions). Enforce it on the server for every request — never trust the client to hide a button.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleDesign two roles for a blog API and which endpoints each can hit.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>reader: GET /posts
author: GET/POST/PATCH/DELETE /posts
→ server checks the role on every write</pre></body></html>
▶ Open the interactive comic issue
‹ Authentication · Who Are YouApi Keys · The Simplest Secret ›