Home/Labs/AuthN vs AuthZ Pipeline
All 280 Labs
INTERACTIVE LAB🔀

Authentication vs Authorization Pipeline Lab (Interactive)

Route requests through identity and permission gates to see 401, 403, and masked 404 decisions. Toggle tokens, roles, and actions to watch identity proofing and policy checks enforced as separate gates, including resource-masking that turns 403 into 404.

AuthN vs AuthZ Request Pipeline

Drive a request through the identity gate, then the PEP/PDP policy gate, and watch 401, 403, and masked 404 responses diverge.

403 Forbidden
AuthN (Edge Gateway + IdP)0.05ms · PASS

JWT signature + exp verified. Subject context injected: sub=usr_48291, role=editor

→PEP (Service Middleware)0.5ms · PASS

Intercepted DELETE /documents/42, extracted context, queried PDP.

→PDP (OPA Policy Engine)0.2ms · FAIL

Role "editor" lacks DELETE on document:42 → DENY

Identity verified, but the role lacks the required permission for this action. Total pipeline cost: 0.75ms. 401 means "we do not know who you are"; 403 means "we know you, and the answer is no."

How It Works Under the Hood

Authentication answers who you are; authorization answers whether you may act, and conflating them breaks both auditability and security. This lab routes each request through a pipeline: bearer-token parsing, expiry and signature verification, then a policy decision point lookup with resource-level checks. Missing or expired credentials return 401 with a WWW-Authenticate header; valid identity but forbidden action returns 403; and production systems often mask 403 as 404 so attackers cannot enumerate which resources exist. Each gate adds measurable latency, showing why co-locating the PDP with the enforcement point matters.

Core Architectural Principles

  • 401 short-circuits before any policy lookup; only verified identities can ever reach the 403 branch.
  • A masking toggle rewrites 403 to 404, denying resource-existence leaks to enumeration attacks.
  • Remote versus sidecar PDP placement changes per-request decision latency by roughly 40 ms.
Interview Round Script

Separate the primitives explicitly: authentication proves identity, authorization evaluates a policy. State that 401 means unauthenticated while 403 means authenticated-but-forbidden, then level up with 404-masking against IDOR enumeration and centralized PDP/PEP placement with Open Policy Agent. Mentioning WWW-Authenticate and per-object (not just per-role) checks signals production experience.

Key Trade-Offs

Layered gates give clean audit semantics but stack latency, and masking 403 as 404 costs legitimate clients debuggability.

Related Curriculum Chapter

Authentication vs Authorization: The Core Security Primitives

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs