DAY 3 · MODULE 9
Authorization & Access Control
Understand why authenticated users still need role and permission checks before accessing resources.
Understand the concept
Authentication vs authorization
Roles
Permissions
Server-side checks
Direct URL access
Least privilege
Why this matters
Access control must be enforced on the server for every protected action, not only hidden in the user interface.
See what happens internally
Interactive visualization loads here.
Stage 2 Interactive Lab
Open Interactive LabOperate this concept in a larger realtime simulation and save your practical score.
Perform the activity
- Compare student and trainer permissions in CyberForge.
- Attempt only permitted navigation.
- Review server-side role-check logic.
Workshop safety: Activities involving scanning, web vulnerabilities or security testing must be performed only on the assigned training target or intentionally vulnerable lab.
Read and understand the working example
if (!in_array($user["role"], ["trainer","admin"])) {
deny_access();
}This example is shown for guided learning. Real host/network execution is reserved for the isolated cyber-range stage.
Prove your understanding
Explain why hiding an Admin button is not enough to secure the Admin page.