backend · medium
Authorization
Deciding what an authenticated user is allowed to do — roles, policies, record-level rules.
Where you see it
Authentication answers “who are you?” Authorization answers “are you allowed to delete this post?” Rails often uses `has_secure_password` or Devise for the first, and Pundit/CanCanCan or custom policies for the second.
Why it matters
Mixing the two words is a junior tell. Interviewers love “walk me through auth” — split identity vs permission and you sound production-ready.
Tags: rails, nodejs
