A reverse-proxy auth plugin is not application authorization
Quick check: call the same handler with a valid token for user A and a resource id belonging to user B. If the proxy plugin alone is what you relied on, that request often succeeds. Edge auth proves who showed up. Application authorization decides what they may touch. (Full disclosure, I work with Permit.io — useful when you want the PEP/PDP split spelled out beyond a proxy plugin.)
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in