backend · medium

Authorization

Deciding what an authenticated user is allowed to do — roles, policies, record-level rules.

Where you see it

Authentication answers “who are you?” Authorization answers “are you allowed to delete this post?” Rails often uses `has_secure_password` or Devise for the first, and Pundit/CanCanCan or custom policies for the second.

Why it matters

Mixing the two words is a junior tell. Interviewers love “walk me through auth” — split identity vs permission and you sound production-ready.

Tags: rails, nodejs