DAY 3 · MODULE 9

Authorization & Access Control

Understand why authenticated users still need role and permission checks before accessing resources.

50 minRole-check walkthroughIn Progress
01 · LEARN

Understand the concept

Authentication vs authorization
Roles
Permissions
Server-side checks
Direct URL access
Least privilege
Why this matters

Access control must be enforced on the server for every protected action, not only hidden in the user interface.

02 · VISUALIZE

See what happens internally

Interactive visualization loads here.
Stage 2 Interactive Lab

Operate this concept in a larger realtime simulation and save your practical score.

Open Interactive Lab
03 · PRACTICAL

Perform the activity

  1. Compare student and trainer permissions in CyberForge.
  2. Attempt only permitted navigation.
  3. Review server-side role-check logic.
Workshop safety: Activities involving scanning, web vulnerabilities or security testing must be performed only on the assigned training target or intentionally vulnerable lab.
04 · CODE / COMMANDS

Read and understand the working example

if (!in_array($user["role"], ["trainer","admin"])) {
    deny_access();
}

This example is shown for guided learning. Real host/network execution is reserved for the isolated cyber-range stage.

05 · CHALLENGE

Prove your understanding

Explain why hiding an Admin button is not enough to secure the Admin page.

Login to Save Progress