Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I came on to say much the same thing: a lot of authorization policies are very basic "is this a request by an authenticated user or service."

But I also think the fact that they both get abbreviated to "auth" also causes a lot of bad mental modeling and poor communication.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: