Authentication vs Authorization Pipeline Lab (Interactive)
Route requests through identity and permission gates to see 401, 403, and masked 404 decisions. Toggle tokens, roles, and actions to watch identity proofing and policy checks enforced as separate gates, including resource-masking that turns 403 into 404.
AuthN vs AuthZ Request Pipeline
Drive a request through the identity gate, then the PEP/PDP policy gate, and watch 401, 403, and masked 404 responses diverge.
JWT signature + exp verified. Subject context injected: sub=usr_48291, role=editor
Intercepted DELETE /documents/42, extracted context, queried PDP.
Role "editor" lacks DELETE on document:42 → DENY
Identity verified, but the role lacks the required permission for this action. Total pipeline cost: 0.75ms. 401 means "we do not know who you are"; 403 means "we know you, and the answer is no."
How It Works Under the Hood
Authentication answers who you are; authorization answers whether you may act, and conflating them breaks both auditability and security. This lab routes each request through a pipeline: bearer-token parsing, expiry and signature verification, then a policy decision point lookup with resource-level checks. Missing or expired credentials return 401 with a WWW-Authenticate header; valid identity but forbidden action returns 403; and production systems often mask 403 as 404 so attackers cannot enumerate which resources exist. Each gate adds measurable latency, showing why co-locating the PDP with the enforcement point matters.
Core Architectural Principles
- 401 short-circuits before any policy lookup; only verified identities can ever reach the 403 branch.
- A masking toggle rewrites 403 to 404, denying resource-existence leaks to enumeration attacks.
- Remote versus sidecar PDP placement changes per-request decision latency by roughly 40 ms.
Separate the primitives explicitly: authentication proves identity, authorization evaluates a policy. State that 401 means unauthenticated while 403 means authenticated-but-forbidden, then level up with 404-masking against IDOR enumeration and centralized PDP/PEP placement with Open Policy Agent. Mentioning WWW-Authenticate and per-object (not just per-role) checks signals production experience.
Layered gates give clean audit semantics but stack latency, and masking 403 as 404 costs legitimate clients debuggability.