Authorization
Studies in this cluster, in series order. Each one keeps its own URL.
Security
AuthN, AuthZ, OAuth/OIDC, OWASP web attacks (injection, XSS, CSRF, SSRF, CORS), secrets/KMS, tokens, and service identity you can defend in interviews.
Authorization
6 studies- 1.Authorization — RBAC, ABAC, ReBAC & Policy EnginesHub decision tree for AuthZ models and PEP/PDP placement; AuthN left to OAuth & OIDC cluster.
- 2.RBAC — Roles, Permissions & Role ExplosionRoles, permissions, and how role explosion pushes teams toward ABAC/ReBAC.
- 3.ABAC — Attributes, Policies, PDP & PEPAttribute-based policies with PDP/PEP separation for env and resource attributes.
- 4.ReBAC & Zanzibar — Relationship Tuples & ConsistencyRelationship-based auth with Zanzibar-style tuples and consistency tradeoffs for sharing graphs.
- 5.Policy Engines — OPA/Rego vs Cedar vs CustomComparative OPA/Rego vs Cedar vs custom if/else; treat policies as audited code.
- 6.AuthZ Enforcement — Gateway, Service & Data FiltersEnforce at gateway + service + data filters; fail closed; defense in depth for AuthZ.