InterviewVault
Welcome back, Sujit Kumar Mishra
Admin
SK Mishra
Revision Mode
Document technical questions and best-practice answers.
Have you ever worked on Authentication and Authorization phase of any application development? Can you explain these processes in detail?
Authentication is about confirming “Who are you?”
It checks if someone is really who they say they are.
Example: When you log in to an app with your username and password, the system checks your identity.
(Other ways: PIN, OTP, fingerprint, or face recognition.)
Authorization is about “What are you allowed to do?”
It decides what actions or information you can access after you are authenticated.
Example: After you log in, you might be able to view your profile, but only admins can change system settings.
In summary:
- Authentication = Proving your identity
- Authorization = Checking your permissions
Easy way to remember:
- First, the system asks “Who are you?” (Authentication)
- Then, it asks “What can you do?” (Authorization)
Both steps are important for keeping applications secure and ensuring users only access what they’re allowed to.