Knowing who your authenticated user is and whether they have access to your application is one thing. Figuring out if they should be able to perform a certain action on a specific resource is another. Protecting our data and allowing users to only do what they should be allowed to do can become quite complex as your application grows. Luckily there are multiple authorization approaches available. Wondering what the best solution for your application is? Let’s find out how we can protect our content by using roles and permissions, or attribute based authorization all the way to fine grained authorization looking for relationships between the user, actions and resources.
In this talk we will go over some of the more common authorization approaches, starting with Role-Based Authorization, going to Attribute-Based Authorization and ending up with a fine-grained authorization solution using Relationship-Base Authorization. The audience does not need any specific knowledge about cryptography as this talk will go through the basics. Some programming knowledge can be useful but not necessary.
Creator of SolidJS, Netlify | USA
Engineer (Web + Golang), GDE, epilot GmbH | Germany
Chief Technology Officer, Builder.io | USA
Principal Serverless Specialist Solutions Architect, AWS | UK
Founder, HiRez.io | Israel
Director of Technology, Builder.io | USA
Trainer and consultant, push-based.io | Austria
Full Stack Team Lead, Sapiens | Israel
Front End Guild Manager, Next Insurance | Israel
Developer Relations Engineer, Storyblok | Germany
CTO, Vizlib | Germany
Development Manager, BEC | Poland
Senior Software Developer, JetBrains | Poland
Senior Frontend Developer, BigPicture | Poland
Staff Developer Advocate Engineer, Auth0 | Belgium
GDE, Senior Software Engineer, Celonis | Germany
Managing Delivery Architect, Capgemini | Poland
Senior Consultant, Inmeta | Norway
Developer Advocate, OLX | Portugal
Teacher and Consultant, ngIndia | India
Head of DevRel, SeMI Technologies | Denmark
Sign up to receive updates about JS Poland, including workshops, speaker previews, ticket launches, JS Awards, JavaScript Master Podcast, Behind the Code Magazine, CFP details and other exclusive content. We won’t spam you and will only send you emails we genuinely think you’ll find interesting. You can unsubscribe at any time and you can find more information here.