Wrapping Up
Having users sign in to get access to advanced functionality isn’t always enough. Access control lets you differentiate between users and enforce what they can access. In this chapter, we discussed the similarities and differences of various access control methods.
Then we moved on to discuss how access validation should always be done as close to the actual operation as possible. We also established that you should avoid direct object references to privileged objects where possible. And finally, we covered that you shouldn’t just validate a user’s access level but also validate access to specific objects.
We’ve set up our full application stack, but we’re missing one vital component—functionality. In the next chapters we’ll discuss ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access