Earlier quoted context omitted.
This has already been solved well-enough with AuthN and AuthZ as distinct names.
UK is rotating in its decaying royal grave
Authorization terminology is a mess: Let's fix it
31–40 of 91 posts
Re: Authorization terminology is a mess: Let's fix it
#32Nice! I'd like to fix the prior abstract. Auth and auth upsets me greatly cos we have: Authentication & Authorization and we call both/either auth. Hence please help me make this a thing: AuthENTIcation & AuthORIzation : ENTI & ORI ENTI- can you enter, ORI (or ORIZ) what can you do?
I don't mean to quarrel about it, but I understood Authentication to be closer to identification. To provide "adequate proof that you are actually who you claim to be".
Even the "can you enter" question falls under authorization; "does the user have appropriate permissions?" Entering is just one of perhaps many subsequent levels of permissions.
Re: Authorization terminology is a mess: Let's fix it
#33Earlier quoted context omitted.
> Probably someone who never confuses “empathy” and “sympathy” while also carefully distinguishing between “should” and “ought”. What do you mean by this?
Not sure what's giving you a pause there?
Re: Authorization terminology is a mess: Let's fix it
#34Re: Authorization terminology is a mess: Let's fix it
#35Nice! I'd like to fix the prior abstract. Auth and auth upsets me greatly cos we have: Authentication & Authorization and we call both/either auth. Hence please help me make this a thing: AuthENTIcation & AuthORIzation : ENTI & ORI ENTI- can you enter, ORI (or ORIZ) what can you do?
> ENTI- can you enter, ORI (or ORIZ) what can you do? I don't mean to quarrel about it, but I understood Authentication to be closer to identification. To provide "adequate proof that you are actually who you claim to be". Even the "can you enter" question falls under authorization; "does the user have appropriate permissions?" Entering is just one of perhaps many subsequent levels of permissions.
But not all systems work this way. There are some systems where you can log in successfully, but then are immediately escorted out because the "can you enter" question has secondary considerations or is decided once identity has been established based on a larger criteria. Expired accounts in some systems work exactly like this.
Re: Authorization terminology is a mess: Let's fix it
#36Earlier quoted context omitted.
I have more experience with authorization than most engineers, even engineers who have some experience with authn/authz, and I have no idea what that "subject can utter the action" or "transfer of nouns and verbs to perform the utterances" could mean
They clearly mean capabilities. https://en.wikipedia.org/wiki/Capability-based_security > Capabilities achieve their objective of improving system security by being used in place of forgeable references. A forgeable reference (for example, a path name) identifies an object, but does not specify which access rights are appropriate for that object and the user program which holds that reference. Consequently, any attem…
https://capnproto.org (used by Cloudflare)
https://spritely.institute/goblins (with wasm support via Hoot)
https://ocapn.org (where things come together in a future open standard)
Re: Authorization terminology is a mess: Let's fix it
#37Re: Authorization terminology is a mess: Let's fix it
#38Re: Authorization terminology is a mess: Let's fix it
#39turns out naming is important
I'm maintaining a document called Tricksy words with multiple meanings that cause endless confusion and strife Just in the past year I have wasted several months pulling my hair out due to incorrectly named projects. It really does turn out naming is important!
The team using Salesforce, the data warehouse team, the application development teams, all with different mental models of what "we added 5,000 users today" actually meant in concrete terms.
Re: Authorization terminology is a mess: Let's fix it
#40Unclosable cookie banner. Top notch website engineering.