Who are you? What can you do?
Two different questions, often confused. Getting the first right and the second wrong is one of the most common security bugs. OWASP ranks it the top web app risk.
Authentication · Who
Passwords
Hashed, never stored as typed
Sign in with…
Google, Microsoft, GitHub
Magic links
A one-time link by email
Two-factor
A code as a second check
Authorisation · What
Roles
Staff, manager, admin
Ownership
Only your own records
Every request
Checked on the server
Least access
Start with none, add
Source: OWASP Top 10:2025 ↗
Borrow the login. Check permissions on every request.