Authentication & security

Authorization

Authorization decides what an identified requester is allowed to do, such as reading a project's events or publishing an update to a shared room.

Also found under: Access control, Permissions, RBAC

How it works

Permissions can come from ownership, membership, roles or other application rules. Role-based access control, or RBAC, is one approach rather than a synonym for every authorization system. Make the decision on a trusted server using the resource requested, not just a client-provided assertion.

In a Pubb integration

Before producing a Pubb subscription signature, check that the authenticated user can access the requested private or presence channel. Also authorize business actions before publishing events with your app secret.

Understand channel access

A practical example

An editor may publish document changes, while a viewer may only receive them. Both users are authenticated, but their allowed actions differ.