-
Notifications
You must be signed in to change notification settings - Fork 9
Expand file tree
/
Copy pathtranslate.samples.mjs
More file actions
716 lines (453 loc) ยท 38.7 KB
/
Copy pathtranslate.samples.mjs
File metadata and controls
716 lines (453 loc) ยท 38.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
/* eslint-disable max-lines */
export const sampleInput = `---
sidebar_position: 2
---
# Authentication vs. authorization
The difference between **authentication** and **authorization** can be summarized as follows:
- **Authentication** answers the question โWhich identity do you own?โ
- **Authorization** answers the question โWhat can you do?โ
For a complete customer identity and access management (CIAM) introduction, you can refer to our CIAM series:
- [CIAM 101: Authentication, Identity, SSO](https://blog.logto.io/ciam-101-intro-authn-sso/)
- [CIAM 102: Authorization & Role-based Access Control](https://blog.logto.io/ciam-102-authz-and-rbac/)
## Authentication \\{#authentication}
Logto supports various interactive and non-interactive authentication methods, for example:
- **Sign-in experience**: The authentication process for end-users.
- **Machine-to-machine (M2M) authentication**: The authentication process for services or applications.
The ultimate goal of authentication is dramatically simple: to verify and get the unique identifier of the entity (in Logto, a user or an application).
## Authorization \\{#authorization}
In Logto, authorization is done through role-based access control (RBAC). It gives you the complete control to manage the access of your users or M2M applications to the following:
- **API resources**: A global entity that represents by an absolute URI.
- **Organizations**: A group of users or applications.
- **Organization API resources**: An API resource that belongs to an organization.
To learn more about these concepts, you can refer to the following resources:
- [Role-based access control (RBAC)](/authorization/role-based-access-control)
- [Organizations (Multi-tenancy)](/organizations)
Here's a visual representation of the relationship between these concepts:
\`\`\`mermaid
graph TD
subgraph Resources
R(API resources)
O(Organizations)
OR(Organization API resources)
end
subgraph Identities
U(Users)
A(M2M applications)
end
\`\`\`
In a nutshell, authorization is about defining the rules that determine what entities in the "Identities" group can access the entities in the "Resources" group.
## Frequently asked questions \\{#frequently-asked-questions}
### I need to specify which users can sign in to an application \\{#i-need-to-specify-which-users-can-sign-in-to-an-application}
Due to the nature of single sign-on (SSO), Logto currently does not support using applications as resources. Instead, you can define API resources and permissions to control access to your resources.
### I need my users to sign in to an organization \\{#i-need-my-users-to-sign-in-to-an-organization}
As mentioned earlier, authentication involves verifying the identity of an entity, while access control is handled through authorization. Therefore:
- Determining which organization(s) a user belongs to is an authorization concern.
- The sign-in process is an authentication concern.
This means that there is no concept of "signing in to an organization" in Logto. Once a user is authenticated, they can be authorized to access all resources (including organization resources) based on the defined permissions.
This model is efficient and clear, as it separates the concerns of authentication and authorization. All modern SaaS applications, such as GitHub and Notion, follow this model.
However, there are some cases where you need to establish 1-1 mappings between user sources and organizations. In this case, [enterprise SSO](/end-user-flows/enterprise-sso) and [organization Just-in-Time (JIT) provisioning](/organizations/just-in-time-provisioning) can be helpful.
### Our customers need custom branding for their sign-in pages \\{#our-customers-need-custom-branding-for-their-sign-in-pages}
Please check out [app-specific branding](/customization/match-your-brand/#app-specific-branding) and [organization-specific branding](/customization/match-your-brand/#organization-specific-branding) for related configurations.
`;
/** The sample translations to align the baseline. */
export const sampleTranslations = Object.freeze({
de: `---
sidebar_position: 2
---
# Authentifizierung vs. Autorisierung
Der Unterschied zwischen **Authentifizierung** und **Autorisierung** lรคsst sich wie folgt zusammenfassen:
- **Authentifizierung (Authentication)** beantwortet die Frage โWelche Identitรคt besitzt du?โ
- **Autorisierung (Authorization)** beantwortet die Frage โWas kannst du tun?โ
Fรผr eine vollstรคndige Einfรผhrung in das Customer Identity and Access Management (CIAM) kannst du auf unsere CIAM-Serie verweisen:
- [CIAM 101: Authentication, Identity, SSO](https://blog.logto.io/ciam-101-intro-authn-sso/)
- [CIAM 102: Authorization & Role-based Access Control](https://blog.logto.io/ciam-102-authz-and-rbac/)
## Authentifizierung \\{#authentication}
Logto unterstรผtzt verschiedene interaktive und nicht-interaktive Authentifizierungsmethoden, zum Beispiel:
- **Anmeldeerfahrung**: Der Authentifizierungsprozess fรผr Endbenutzer.
- **Maschine-zu-Maschine (M2M) Authentifizierung**: Der Authentifizierungsprozess fรผr Dienste oder Anwendungen.
Das ultimative Ziel der Authentifizierung ist denkbar einfach: die รberprรผfung und das Erhalten des eindeutigen Identifikators der Entitรคt (in Logto, ein Benutzer oder eine Anwendung).
## Autorisierung \\{#authorization}
In Logto erfolgt die Autorisierung durch rollenbasierte Zugangskontrolle (RBAC). Sie gibt dir die vollstรคndige Kontrolle รผber die Verwaltung des Zugangs deiner Benutzer oder M2M-Anwendungen zu den folgenden:
- **API-Ressourcen**: Eine globale Entitรคt, die durch eine absolute URI dargestellt wird.
- **Organisationen**: Eine Gruppe von Benutzern oder Anwendungen.
- **Organisations-API-Ressourcen**: Eine API-Ressource, die zu einer Organisation gehรถrt.
Um mehr รผber diese Konzepte zu erfahren, kannst du auf die folgenden Ressourcen verweisen:
- [Rollenbasierte Zugangskontrolle (RBAC)](/authorization/role-based-access-control)
- [Organisationen (Multi-Tenancy)](/organizations)
Hier ist eine visuelle Darstellung der Beziehung zwischen diesen Konzepten:
\`\`\`mermaid
graph TD
subgraph Resources
R(API-Ressourcen)
O(Organisationen)
OR(Organisations-API-Ressourcen)
end
subgraph Identities
U(Benutzer)
A(M2M-Anwendungen)
end
\`\`\`
Kurz gesagt, bei der Autorisierung geht es darum, die Regeln festzulegen, die bestimmen, welche Entitรคten in der Gruppe "Identitรคten" auf die Entitรคten in der Gruppe "Ressourcen" zugreifen kรถnnen.
## Hรคufig gestellte Fragen \\{#frequently-asked-questions}
### Ich muss angeben, welche Benutzer sich bei einer Anwendung anmelden kรถnnen \\{#i-need-to-specify-which-users-can-sign-in-to-an-application}
Aufgrund der Natur von Single Sign-On (SSO) unterstรผtzt Logto derzeit nicht die Verwendung von Anwendungen als Ressourcen. Stattdessen kannst du API-Ressourcen und Berechtigungen definieren, um den Zugriff auf deine Ressourcen zu steuern.
### Ich benรถtige, dass sich meine Benutzer bei einer Organisation anmelden \\{#i-need-my-users-to-sign-in-to-an-organization}
Wie bereits erwรคhnt, beinhaltet die Authentifizierung die รberprรผfung der Identitรคt einer Entitรคt, wรคhrend die Zugangskontrolle durch Autorisierung gehandhabt wird. Daher:
- Die Bestimmung, zu welcher(n) Organisation(en) ein Benutzer gehรถrt, ist ein Autorisierungsanliegen.
- Der Anmeldeprozess ist ein Authentifizierungsanliegen.
Das bedeutet, dass es in Logto kein Konzept des "Anmeldens bei einer Organisation" gibt. Sobald ein Benutzer authentifiziert ist, kann er basierend auf den definierten Berechtigungen autorisiert werden, auf alle Ressourcen (einschlieรlich Organisationsressourcen) zuzugreifen.
Dieses Modell ist effizient und klar, da es die Anliegen der Authentifizierung und Autorisierung trennt. Alle modernen SaaS-Anwendungen, wie GitHub und Notion, folgen diesem Modell.
Es gibt jedoch einige Fรคlle, in denen du 1-1-Zuordnungen zwischen Benutzerquellen und Organisationen herstellen musst. In diesem Fall kรถnnen [Enterprise SSO](/end-user-flows/enterprise-sso) und [Organisation Just-in-Time (JIT) Bereitstellung](/organizations/just-in-time-provisioning) hilfreich sein.
### Unsere Kunden benรถtigen ein individuelles Branding fรผr ihre Anmeldeseiten \\{#our-customers-need-custom-branding-for-their-sign-in-pages}
Bitte schaue dir [App-spezifisches Branding](/customization/match-your-brand/#app-specific-branding) und [Organisationsspezifisches Branding](/customization/match-your-brand/#organization-specific-branding) fรผr verwandte Konfigurationen an.
`,
es: `---
sidebar_position: 2
---
# Autenticaciรณn vs. autorizaciรณn
La diferencia entre **autenticaciรณn** y **autorizaciรณn** se puede resumir de la siguiente manera:
- **Autenticaciรณn (Authentication)** responde a la pregunta "ยฟQuรฉ identidad posees?"
- **Autorizaciรณn (Authorization)** responde a la pregunta "ยฟQuรฉ puedes hacer?"
Para una introducciรณn completa a la gestiรณn de identidad y acceso del cliente (CIAM), puedes consultar nuestra serie de CIAM:
- [CIAM 101: Authentication, Identity, SSO](https://blog.logto.io/ciam-101-intro-authn-sso/)
- [CIAM 102: Authorization & Role-based Access Control](https://blog.logto.io/ciam-102-authz-and-rbac/)
## Autenticaciรณn \\{#authentication}
Logto admite varios mรฉtodos de autenticaciรณn interactivos y no interactivos, por ejemplo:
- **Experiencia de inicio de sesiรณn**: El proceso de autenticaciรณn para los usuarios finales.
- **Autenticaciรณn mรกquina a mรกquina (M2M)**: El proceso de autenticaciรณn para servicios o aplicaciones.
El objetivo final de la autenticaciรณn es extremadamente simple: verificar y obtener el identificador รบnico de la entidad (en Logto, un usuario o una aplicaciรณn).
## Autorizaciรณn \\{#authorization}
En Logto, la autorizaciรณn se realiza a travรฉs del control de acceso basado en roles (RBAC). Te da el control completo para gestionar el acceso de tus usuarios o aplicaciones M2M a lo siguiente:
- **Recursos de API (API resources)**: Una entidad global representada por un URI absoluto.
- **Organizaciones (Organizations)**: Un grupo de usuarios o aplicaciones.
- **Recursos de API de la organizaciรณn (Organization API resources)**: Un recurso de API que pertenece a una organizaciรณn.
Para aprender mรกs sobre estos conceptos, puedes consultar los siguientes recursos:
- [Control de acceso basado en roles (RBAC)](/authorization/role-based-access-control)
- [Organizaciones (Multi-tenancy)](/organizations)
Aquรญ tienes una representaciรณn visual de la relaciรณn entre estos conceptos:
\`\`\`mermaid
graph TD
subgraph Resources
R(Recursos de API)
O(Organizaciones)
OR(Recursos de API de la organizaciรณn)
end
subgraph Identities
U(Usuarios)
A(Aplicaciones M2M)
end
\`\`\`
En resumen, la autorizaciรณn se trata de definir las reglas que determinan quรฉ entidades en el grupo "Identidades" pueden acceder a las entidades en el grupo "Recursos".
## Preguntas frecuentes \\{#frequently-asked-questions}
### Necesito especificar quรฉ usuarios pueden iniciar sesiรณn en una aplicaciรณn \\{#i-need-to-specify-which-users-can-sign-in-to-an-application}
Debido a la naturaleza del inicio de sesiรณn รบnico (SSO), Logto actualmente no admite el uso de aplicaciones como recursos. En su lugar, puedes definir recursos de API y permisos para controlar el acceso a tus recursos.
### Necesito que mis usuarios inicien sesiรณn en una organizaciรณn \\{#i-need-my-users-to-sign-in-to-an-organization}
Como se mencionรณ anteriormente, la autenticaciรณn implica verificar la identidad de una entidad, mientras que el control de acceso se maneja a travรฉs de la autorizaciรณn. Por lo tanto:
- Determinar a quรฉ organizaciรณn(es) pertenece un usuario es una preocupaciรณn de autorizaciรณn.
- El proceso de inicio de sesiรณn es una preocupaciรณn de autenticaciรณn.
Esto significa que no hay un concepto de "iniciar sesiรณn en una organizaciรณn" en Logto. Una vez que un usuario estรก autenticado, puede ser autorizado para acceder a todos los recursos (incluidos los recursos de la organizaciรณn) basรกndose en los permisos definidos.
Este modelo es eficiente y claro, ya que separa las preocupaciones de autenticaciรณn y autorizaciรณn. Todas las aplicaciones SaaS modernas, como GitHub y Notion, siguen este modelo.
Sin embargo, hay algunos casos en los que necesitas establecer mapeos 1-1 entre fuentes de usuarios y organizaciones. En este caso, el [SSO empresarial](/end-user-flows/enterprise-sso) y el [aprovisionamiento Just-in-Time (JIT) de la organizaciรณn](/organizations/just-in-time-provisioning) pueden ser รบtiles.
### Nuestros clientes necesitan personalizaciรณn de marca para sus pรกginas de inicio de sesiรณn \\{#our-customers-need-custom-branding-for-their-sign-in-pages}
Por favor, consulta [personalizaciรณn especรญfica de la aplicaciรณn](/customization/match-your-brand/#app-specific-branding) y [personalizaciรณn especรญfica de la organizaciรณn](/customization/match-your-brand/#organization-specific-branding) para configuraciones relacionadas.`,
fr: `---
sidebar_position: 2
---
# Authentification vs. autorisation
La diffรฉrence entre **l'authentification** et **l'autorisation** peut รชtre rรฉsumรฉe comme suit :
- **Authentification (Authentication)** rรฉpond ร la question "Quelle identitรฉ possรฉdez-vous ?"
- **Autorisation (Authorization)** rรฉpond ร la question "Que pouvez-vous faire ?"
Pour une introduction complรจte ร la gestion des identitรฉs et des accรจs des clients (CIAM), vous pouvez vous rรฉfรฉrer ร notre sรฉrie CIAM :
- [CIAM 101 : Authentification, Identitรฉ, SSO](https://blog.logto.io/ciam-101-intro-authn-sso/)
- [CIAM 102 : Autorisation & Contrรดle dโaccรจs basรฉ sur les rรดles (RBAC)](https://blog.logto.io/ciam-102-authz-and-rbac/)
## Authentification \\{#authentication}
Logto prend en charge diverses mรฉthodes d'authentification interactives et non interactives, par exemple :
- **Expรฉrience de connexion** : Le processus d'authentification pour les utilisateurs finaux.
- **Authentification machine ร machine (M2M)** : Le processus d'authentification pour les services ou les applications.
L'objectif ultime de l'authentification est extrรชmement simple : vรฉrifier et obtenir l'identifiant unique de l'entitรฉ (dans Logto, un utilisateur ou une application).
## Autorisation \\{#authorization}
Dans Logto, l'autorisation est effectuรฉe via le contrรดle dโaccรจs basรฉ sur les rรดles (RBAC). Cela vous donne un contrรดle complet pour gรฉrer l'accรจs de vos utilisateurs ou applications M2M aux รฉlรฉments suivants :
- **Ressources API** : Une entitรฉ globale reprรฉsentรฉe par un URI absolu.
- **Organisations** : Un groupe d'utilisateurs ou d'applications.
- **Ressources API d'organisation** : Une ressource API qui appartient ร une organisation.
Pour en savoir plus sur ces concepts, vous pouvez vous rรฉfรฉrer aux ressources suivantes :
- [Contrรดle dโaccรจs basรฉ sur les rรดles (RBAC)](/authorization/role-based-access-control)
- [Organisations (Multi-tenancy)](/organizations)
Voici une reprรฉsentation visuelle de la relation entre ces concepts :
\`\`\`mermaid
graph TD
subgraph Resources
R(Ressources API)
O(Organisations)
OR(Ressources API d'organisation)
end
subgraph Identities
U(Utilisateurs)
A(Applications M2M)
end
\`\`\`
En rรฉsumรฉ, l'autorisation consiste ร dรฉfinir les rรจgles qui dรฉterminent quelles entitรฉs du groupe "Identitรฉs" peuvent accรฉder aux entitรฉs du groupe "Resources".
## Questions frรฉquemment posรฉes \\{#frequently-asked-questions}
### Je dois spรฉcifier quels utilisateurs peuvent se connecter ร une application \\{#i-need-to-specify-which-users-can-sign-in-to-an-application}
En raison de la nature de l'authentification unique (SSO), Logto ne prend actuellement pas en charge l'utilisation des applications en tant que ressources. Au lieu de cela, vous pouvez dรฉfinir des ressources API et des permissions pour contrรดler l'accรจs ร vos ressources.
### Je veux que mes utilisateurs se connectent ร une organisation \\{#i-need-my-users-to-sign-in-to-an-organization}
Comme mentionnรฉ prรฉcรฉdemment, l'authentification implique la vรฉrification de l'identitรฉ d'une entitรฉ, tandis que le contrรดle d'accรจs est gรฉrรฉ par l'autorisation. Par consรฉquent :
- Dรฉterminer ร quelle(s) organisation(s) un utilisateur appartient est une question d'autorisation.
- Le processus de connexion est une question d'authentification.
Cela signifie qu'il n'y a pas de concept de "connexion ร une organisation" dans Logto. Une fois qu'un utilisateur est authentifiรฉ, il peut รชtre autorisรฉ ร accรฉder ร toutes les ressources (y compris les ressources d'organisation) en fonction des permissions dรฉfinies.
Ce modรจle est efficace et clair, car il sรฉpare les prรฉoccupations de l'authentification et de l'autorisation. Toutes les applications SaaS modernes, telles que GitHub et Notion, suivent ce modรจle.
Cependant, il existe certains cas oรน vous devez รฉtablir des correspondances 1-1 entre les sources d'utilisateurs et les organisations. Dans ce cas, [SSO dโentreprise](/end-user-flows/enterprise-sso) et [approvisionnement Just-in-Time (JIT) d'organisation](/organizations/just-in-time-provisioning) peuvent รชtre utiles.
### Nos clients ont besoin d'une personnalisation de marque pour leurs pages de connexion \\{#our-customers-need-custom-branding-for-their-sign-in-pages}
Veuillez consulter [personnalisation spรฉcifique ร l'application](/customization/match-your-brand/#app-specific-branding) et [personnalisation spรฉcifique ร l'organisation](/customization/match-your-brand/#organization-specific-branding) pour les configurations associรฉes.
`,
'pt-BR': `---
sidebar_position: 2
---
# Autenticaรงรฃo vs. autorizaรงรฃo
A diferenรงa entre **autenticaรงรฃo** e **autorizaรงรฃo** pode ser resumida da seguinte forma:
- **Autenticaรงรฃo (Authentication)** responde ร pergunta "Qual identidade vocรช possui?"
- **Autorizaรงรฃo (Authorization)** responde ร pergunta "O que vocรช pode fazer?"
Para uma introduรงรฃo completa ao gerenciamento de identidade e acesso do cliente (CIAM), vocรช pode consultar nossa sรฉrie CIAM:
- [CIAM 101: Authentication, Identity, SSO](https://blog.logto.io/ciam-101-intro-authn-sso/)
- [CIAM 102: Authorization & Role-based Access Control](https://blog.logto.io/ciam-102-authz-and-rbac/)
## Autenticaรงรฃo (Authentication) \\{#authentication}
Logto suporta vรกrios mรฉtodos de autenticaรงรฃo interativos e nรฃo interativos, por exemplo:
- **Experiรชncia de login**: O processo de autenticaรงรฃo para usuรกrios finais.
- **Autenticaรงรฃo mรกquina para mรกquina (M2M)**: O processo de autenticaรงรฃo para serviรงos ou aplicativos.
O objetivo final da autenticaรงรฃo รฉ dramaticamente simples: verificar e obter o identificador รบnico da entidade (no Logto, um usuรกrio ou um aplicativo).
## Autorizaรงรฃo (Authorization) \\{#authorization}
No Logto, a autorizaรงรฃo รฉ feita atravรฉs do controle de acesso baseado em papel (RBAC). Ele oferece controle total para gerenciar o acesso de seus usuรกrios ou aplicativos M2M aos seguintes:
- **Recursos de API (API resources)**: Uma entidade global representada por um URI absoluto.
- **Organizaรงรตes (Organizations)**: Um grupo de usuรกrios ou aplicativos.
- **Recursos de API da organizaรงรฃo (Organization API resources)**: Um recurso de API que pertence a uma organizaรงรฃo.
Para saber mais sobre esses conceitos, vocรช pode consultar os seguintes recursos:
- [Controle de acesso baseado em papel (RBAC)](/authorization/role-based-access-control)
- [Organizaรงรตes (Multi-tenancy)](/organizations)
Aqui estรก uma representaรงรฃo visual da relaรงรฃo entre esses conceitos:
\`\`\`mermaid
graph TD
subgraph Resources
R(Recursos de API)
O(Organizaรงรตes)
OR(Recursos de API da organizaรงรฃo)
end
subgraph Identities
U(Usuรกrios)
A(Aplicativos M2M)
end
\`\`\`
Em resumo, a autorizaรงรฃo รฉ sobre definir as regras que determinam quais entidades no grupo "Identities" podem acessar as entidades no grupo "Resources".
## Perguntas frequentes \\{#frequently-asked-questions}
### Preciso especificar quais usuรกrios podem fazer login em um aplicativo \\{#i-need-to-specify-which-users-can-sign-in-to-an-application}
Devido ร natureza da autenticaรงรฃo รบnica (SSO), o Logto atualmente nรฃo suporta o uso de aplicativos como recursos. Em vez disso, vocรช pode definir recursos de API e permissรตes para controlar o acesso aos seus recursos.
### Preciso que meus usuรกrios faรงam login em uma organizaรงรฃo \\{#i-need-my-users-to-sign-in-to-an-organization}
Como mencionado anteriormente, a autenticaรงรฃo envolve verificar a identidade de uma entidade, enquanto o controle de acesso รฉ tratado atravรฉs da autorizaรงรฃo. Portanto:
- Determinar a qual(is) organizaรงรฃo(รตes) um usuรกrio pertence รฉ uma preocupaรงรฃo de autorizaรงรฃo.
- O processo de login รฉ uma preocupaรงรฃo de autenticaรงรฃo.
Isso significa que nรฃo hรก conceito de "fazer login em uma organizaรงรฃo" no Logto. Uma vez que um usuรกrio รฉ autenticado, ele pode ser autorizado a acessar todos os recursos (incluindo recursos da organizaรงรฃo) com base nas permissรตes definidas.
Esse modelo รฉ eficiente e claro, pois separa as preocupaรงรตes de autenticaรงรฃo e autorizaรงรฃo. Todos os aplicativos SaaS modernos, como GitHub e Notion, seguem esse modelo.
No entanto, hรก alguns casos em que vocรช precisa estabelecer mapeamentos 1-1 entre fontes de usuรกrios e organizaรงรตes. Nesse caso, [SSO corporativo (Enterprise SSO)](/end-user-flows/enterprise-sso) e [provisionamento Just-in-Time (JIT) da organizaรงรฃo](/organizations/just-in-time-provisioning) podem ser รบteis.
### Nossos clientes precisam de personalizaรงรฃo de marca para suas pรกginas de login \\{#our-customers-need-custom-branding-for-their-sign-in-pages}
Por favor, confira [personalizaรงรฃo especรญfica do aplicativo](/customization/match-your-brand/#app-specific-branding) e [personalizaรงรฃo especรญfica da organizaรงรฃo](/customization/match-your-brand/#organization-specific-branding) para configuraรงรตes relacionadas.`,
ja: `---
sidebar_position: 2
---
# ่ช่จผ (Authentication) ใจ่ชๅฏ (Authorization)
**่ช่จผ (Authentication)** ใจ **่ชๅฏ (Authorization)** ใฎ้ใใฏๆฌกใฎใใใซ่ฆ็ดใงใใพใ๏ผ
- **่ช่จผ (Authentication)** ใฏใใฉใฎใขใคใใณใใฃใใฃใๆๆใใฆใใพใใ๏ผใใจใใ่ณชๅใซ็ญใใพใใ
- **่ชๅฏ (Authorization)** ใฏใไฝใใงใใพใใ๏ผใใจใใ่ณชๅใซ็ญใใพใใ
ๅฎๅ
จใช้กงๅฎขใขใคใใณใใฃใใฃใจใขใฏใปใน็ฎก็ (CIAM) ใฎ็ดนไปใซใคใใฆใฏใCIAM ใทใชใผใบใๅ็
งใงใใพใ๏ผ
- [CIAM 101: ่ช่จผ (Authentication)ใใขใคใใณใใฃใใฃใใทใณใฐใซใตใคใณใชใณ (SSO)](https://blog.logto.io/ciam-101-intro-authn-sso/)
- [CIAM 102: ่ชๅฏ (Authorization) ใจใญใผใซใใผในใฎใขใฏใปในๅถๅพก (RBAC)](https://blog.logto.io/ciam-102-authz-and-rbac/)
## ่ช่จผ (Authentication) \\{#authentication}
Logto ใฏใใใพใใพใชใคใณใฟใฉใฏใใฃใใใใณ้ใคใณใฟใฉใฏใใฃใใช่ช่จผ (Authentication) ๆนๆณใใตใใผใใใฆใใพใใไพใใฐ๏ผ
- **ใตใคใณใคใณไฝ้จ**๏ผใจใณใใฆใผใถใผใฎใใใฎ่ช่จผ (Authentication) ใใญใปในใ
- **ใใทใณ้้ไฟก (M2M) ่ช่จผ (Authentication)**๏ผใตใผใในใพใใฏใขใใชใฑใผใทใงใณใฎใใใฎ่ช่จผ (Authentication) ใใญใปในใ
่ช่จผ (Authentication) ใฎ็ฉถๆฅตใฎ็ฎๆจใฏ้ๅธธใซใทใณใใซใงใ๏ผใจใณใใฃใใฃ๏ผLogto ใงใฏใฆใผใถใผใพใใฏใขใใชใฑใผใทใงใณ๏ผใฎไธๆใฎ่ญๅฅๅญใ็ขบ่ชใๅๅพใใใใจใงใใ
## ่ชๅฏ (Authorization) \\{#authorization}
Logto ใงใฏใ่ชๅฏ (Authorization) ใฏใญใผใซใใผในใฎใขใฏใปในๅถๅพก (RBAC) ใ้ใใฆ่กใใใพใใใใใซใใใๆฌกใฎใขใฏใปในใ็ฎก็ใใใใใฎๅฎๅ
จใชใณใณใใญใผใซใๅฏ่ฝใซใชใใพใ๏ผ
- **API ใชใฝใผใน**๏ผ็ตถๅฏพ URI ใง่กจใใใใฐใญใผใใซใจใณใใฃใใฃใ
- **็ต็น (Organizations)**๏ผใฆใผใถใผใพใใฏใขใใชใฑใผใทใงใณใฎใฐใซใผใใ
- **็ต็น API ใชใฝใผใน**๏ผ็ต็นใซๅฑใใ API ใชใฝใผในใ
ใใใใฎๆฆๅฟตใซใคใใฆ่ฉณใใ็ฅใใซใฏใๆฌกใฎใชใฝใผในใๅ็
งใใฆใใ ใใ๏ผ
- [ใญใผใซใใผในใฎใขใฏใปในๅถๅพก (RBAC)](/authorization/role-based-access-control)
- [็ต็น (ใใซใใใใณใทใผ)](/organizations)
ใใใใฎๆฆๅฟต้ใฎ้ขไฟใ่ฆ่ฆ็ใซ่กจ็พใใใใฎใใใกใใงใ๏ผ
\`\`\`mermaid
graph TD
subgraph Resources
R(API ใชใฝใผใน)
O(็ต็น)
OR(็ต็น API ใชใฝใผใน)
end
subgraph Identities
U(ใฆใผใถใผ)
A(M2M ใขใใชใฑใผใทใงใณ)
end
\`\`\`
่ฆใใใซใ่ชๅฏ (Authorization) ใฏใIdentitiesใใฐใซใผใใฎใจใณใใฃใใฃใใResourcesใใฐใซใผใใฎใจใณใใฃใใฃใซใขใฏใปในใงใใใใฉใใใๆฑบๅฎใใใซใผใซใๅฎ็พฉใใใใจใงใใ
## ใใใใ่ณชๅ \\{#frequently-asked-questions}
### ใขใใชใฑใผใทใงใณใซใตใคใณใคใณใงใใใฆใผใถใผใๆๅฎใใๅฟ
่ฆใใใใพใ \\{#i-need-to-specify-which-users-can-sign-in-to-an-application}
ใทใณใฐใซใตใคใณใชใณ (SSO) ใฎๆง่ณชไธใLogto ใฏ็พๅจใใขใใชใฑใผใทใงใณใใชใฝใผในใจใใฆไฝฟ็จใใใใจใใตใใผใใใฆใใพใใใไปฃใใใซใAPI ใชใฝใผในใจๆจฉ้ใๅฎ็พฉใใฆใชใฝใผในใธใฎใขใฏใปในใๅถๅพกใงใใพใใ
### ใฆใผใถใผใ็ต็นใซใตใคใณใคใณใใๅฟ
่ฆใใใใพใ \\{#i-need-my-users-to-sign-in-to-an-organization}
ๅ่ฟฐใฎใใใซใ่ช่จผ (Authentication) ใฏใจใณใใฃใใฃใฎใขใคใใณใใฃใใฃใ็ขบ่ชใใใใจใงใใใใขใฏใปในๅถๅพกใฏ่ชๅฏ (Authorization) ใซใใฃใฆๅฆ็ใใใพใใใใใใฃใฆ๏ผ
- ใฆใผใถใผใใฉใฎ็ต็นใซๅฑใใฆใใใใๆฑบๅฎใใใใจใฏใ่ชๅฏ (Authorization) ใฎๅ้กใงใใ
- ใตใคใณใคใณใใญใปในใฏใ่ช่จผ (Authentication) ใฎๅ้กใงใใ
ใใใฏใLogto ใซใฏใ็ต็นใซใตใคใณใคใณใใใใจใใๆฆๅฟตใใชใใใจใๆๅณใใพใใใฆใผใถใผใ่ช่จผ (Authentication) ใใใใจใๅฎ็พฉใใใๆจฉ้ใซๅบใฅใใฆใในใฆใฎใชใฝใผใน๏ผ็ต็นใชใฝใผในใๅซใ๏ผใซใขใฏใปในใใๆจฉ้ใไธใใใใพใใ
ใใฎใขใใซใฏใ่ช่จผ (Authentication) ใจ่ชๅฏ (Authorization) ใฎๅ้กใๅ้ขใใใใใๅน็็ใงๆ็ขบใงใใGitHub ใ Notion ใชใฉใฎใในใฆใฎๆๆฐใฎ SaaS ใขใใชใฑใผใทใงใณใฏใใใฎใขใใซใซๅพใฃใฆใใพใใ
ใใ ใใใฆใผใถใผใฝใผในใจ็ต็นใฎ้ใซ 1 ๅฏพ 1 ใฎใใใใณใฐใ็ขบ็ซใใๅฟ
่ฆใใใๅ ดๅใใใใพใใใใฎๅ ดๅใ[ใจใณใฟใผใใฉใคใบใทใณใฐใซใตใคใณใชใณ (SSO)](/end-user-flows/enterprise-sso) ใจ [็ต็นใฎใธใฃในใใคใณใฟใคใ (JIT) ใใญใใธใงใใณใฐ](/organizations/just-in-time-provisioning) ใๅฝน็ซใกใพใใ
### ้กงๅฎขใฏใตใคใณใคใณใใผใธใซใซในใฟใ ใใฉใณใใฃใณใฐใๅฟ
่ฆใจใใฆใใพใ \\{#our-customers-need-custom-branding-for-their-sign-in-pages}
้ข้ฃใใ่จญๅฎใซใคใใฆใฏใ[ใขใใชๅบๆใฎใใฉใณใใฃใณใฐ](/customization/match-your-brand/#app-specific-branding) ใจ [็ต็นๅบๆใฎใใฉใณใใฃใณใฐ](/customization/match-your-brand/#organization-specific-branding) ใ็ขบ่ชใใฆใใ ใใใ
`,
'zh-CN': `---
sidebar_position: 2
---
# ่ฎค่ฏ (Authentication) ไธๆๆ (Authorization)
**่ฎค่ฏ (Authentication)** ๅ **ๆๆ (Authorization)** ไน้ด็ๅบๅซๅฏไปฅๆป็ปๅฆไธ๏ผ
- **่ฎค่ฏ (Authentication)** ๅ็ญไบโไฝ ๆฅๆๅชไธช่บซไปฝ๏ผโ็้ฎ้ข
- **ๆๆ (Authorization)** ๅ็ญไบโไฝ ๅฏไปฅๅไปไน๏ผโ็้ฎ้ข
ๆๅ
ณๅฎๆด็ๅฎขๆท่บซไปฝๅ่ฎฟ้ฎ็ฎก็ (CIAM) ไป็ป๏ผไฝ ๅฏไปฅๅ่ๆไปฌ็ CIAM ็ณปๅ๏ผ
- [CIAM 101: ่ฎค่ฏ (Authentication)ใ่บซไปฝใๅ็น็ปๅฝ (SSO)](https://blog.logto.io/ciam-101-intro-authn-sso/)
- [CIAM 102: ๆๆ (Authorization) ไธๅบไบ่ง่ฒ็่ฎฟ้ฎๆงๅถ (RBAC)](https://blog.logto.io/ciam-102-authz-and-rbac/)
## ่ฎค่ฏ (Authentication) \\{#authentication}
Logto ๆฏๆๅค็งไบคไบๅผๅ้ไบคไบๅผ็่ฎค่ฏ (Authentication) ๆนๆณ๏ผไพๅฆ๏ผ
- **็ปๅฝไฝ้ช**๏ผ็ป็ซฏ็จๆท็่ฎค่ฏ (Authentication) ่ฟ็จใ
- **ๆบๅจๅฏนๆบๅจ (M2M) ่ฎค่ฏ (Authentication)**๏ผๆๅกๆๅบ็จ็จๅบ็่ฎค่ฏ (Authentication) ่ฟ็จใ
่ฎค่ฏ (Authentication) ็ๆ็ป็ฎๆ ้ๅธธ็ฎๅ๏ผ้ช่ฏๅนถ่ทๅๅฎไฝ็ๅฏไธๆ ่ฏ็ฌฆ๏ผๅจ Logto ไธญ๏ผๆฏ็จๆทๆๅบ็จ็จๅบ๏ผใ
## ๆๆ (Authorization) \\{#authorization}
ๅจ Logto ไธญ๏ผๆๆ (Authorization) ๆฏ้่ฟๅบไบ่ง่ฒ็่ฎฟ้ฎๆงๅถ (RBAC) ๅฎๆ็ใๅฎ่ฎฉไฝ ๅฏไปฅๅฎๅ
จๆงๅถ็จๆทๆ M2M ๅบ็จ็จๅบๅฏนไปฅไธๅ
ๅฎน็่ฎฟ้ฎ๏ผ
- **API ่ตๆบ**๏ผ็ฑ็ปๅฏน URI ่กจ็คบ็ๅ
จๅฑๅฎไฝใ
- **็ป็ป (Organizations)**๏ผ็จๆทๆๅบ็จ็จๅบ็็ปใ
- **็ป็ป API ่ตๆบ**๏ผๅฑไบ็ป็ป็ API ่ตๆบใ
่ฆไบ่งฃๆดๅคๅ
ณไบ่ฟไบๆฆๅฟต็ไฟกๆฏ๏ผไฝ ๅฏไปฅๅ่ไปฅไธ่ตๆบ๏ผ
- [ๅบไบ่ง่ฒ็่ฎฟ้ฎๆงๅถ (RBAC)](/authorization/role-based-access-control)
- [็ป็ป (Organizations)๏ผๅค็งๆท๏ผ](/organizations)
ไปฅไธๆฏ่ฟไบๆฆๅฟตไน้ดๅ
ณ็ณป็ๅฏ่งๅ่กจ็คบ๏ผ
\`\`\`mermaid
graph TD
subgraph Resources
R(API ่ตๆบ)
O(็ป็ป (Organizations))
OR(็ป็ป API ่ตๆบ)
end
subgraph Identities
U(็จๆท)
A(M2M ๅบ็จ็จๅบ)
end
\`\`\`
็ฎ่่จไน๏ผๆๆ (Authorization) ๆฏๅ
ณไบๅฎไน่งๅ๏ผไปฅ็กฎๅฎโIdentitiesโ็ปไธญ็ๅฎไฝๅฏไปฅ่ฎฟ้ฎโResourcesโ็ปไธญ็ๅชไบๅฎไฝใ
## ๅธธ่ง้ฎ้ข่งฃ็ญ \\{#frequently-asked-questions}
### ๆ้่ฆๆๅฎๅชไบ็จๆทๅฏไปฅ็ปๅฝๅฐๅบ็จ็จๅบ \\{#i-need-to-specify-which-users-can-sign-in-to-an-application}
็ฑไบๅ็น็ปๅฝ (SSO) ็็นๆง๏ผLogto ็ฎๅไธๆฏๆๅฐๅบ็จ็จๅบ็จไฝ่ตๆบใ็ธๅ๏ผไฝ ๅฏไปฅๅฎไน API ่ตๆบๅๆ้ๆฅๆงๅถๅฏน่ตๆบ็่ฎฟ้ฎใ
### ๆ้่ฆๆ็็จๆท็ปๅฝๅฐไธไธช็ป็ป \\{#i-need-my-users-to-sign-in-to-an-organization}
ๅฆๅๆ่ฟฐ๏ผ่ฎค่ฏ (Authentication) ๆถๅ้ช่ฏๅฎไฝ็่บซไปฝ๏ผ่่ฎฟ้ฎๆงๅถๆฏ้่ฟๆๆ (Authorization) ๅค็็ใๅ ๆญค๏ผ
- ็กฎๅฎ็จๆทๅฑไบๅชไธช็ป็ปๆฏไธไธชๆๆ (Authorization) ้ฎ้ขใ
- ็ปๅฝ่ฟ็จๆฏไธไธช่ฎค่ฏ (Authentication) ้ฎ้ขใ
่ฟๆๅณ็ๅจ Logto ไธญๆฒกๆโ็ปๅฝๅฐ็ป็ปโ็ๆฆๅฟตใไธๆฆ็จๆท่ขซ่ฎค่ฏ (Authentication)๏ผไปไปฌๅฏไปฅๆ นๆฎๅฎไน็ๆ้่ขซๆๆ (Authorization) ่ฎฟ้ฎๆๆ่ตๆบ๏ผๅ
ๆฌ็ป็ป่ตๆบ๏ผใ
่ฟ็งๆจกๅ้ซๆไธๆธ
ๆฐ๏ผๅ ไธบๅฎๅฐ่ฎค่ฏ (Authentication) ๅๆๆ (Authorization) ็ๅ
ณๆณจ็นๅๅผใๆๆ็ฐไปฃ SaaS ๅบ็จ็จๅบ๏ผๅฆ GitHub ๅ Notion๏ผ้ฝ้ตๅพช่ฟ็งๆจกๅใ
็ถ่๏ผๅจๆไบๆ
ๅตไธ๏ผไฝ ้่ฆๅจ็จๆทๆฅๆบๅ็ป็ปไน้ดๅปบ็ซ 1-1 ๆ ๅฐใๅจ่ฟ็งๆ
ๅตไธ๏ผ[ไผไธๅ็น็ปๅฝ (SSO)](/end-user-flows/enterprise-sso) ๅ [็ป็ปๅณๆถ (JIT) ไพๅบ](/organizations/just-in-time-provisioning) ๅฏ่ฝไผๆๆๅธฎๅฉใ
### ๆไปฌ็ๅฎขๆท้่ฆไธบไปไปฌ็็ปๅฝ้กต้ขๅฎๅถๅ็ \\{#our-customers-need-custom-branding-for-their-sign-in-pages}
่ฏทๆฅ็ [ๅบ็จ็จๅบ็นๅฎๅ็](/customization/match-your-brand/#app-specific-branding) ๅ [็ป็ป็นๅฎๅ็](/customization/match-your-brand/#organization-specific-branding) ไปฅ่ทๅ็ธๅ
ณ้
็ฝฎใ
`,
ko: `---
sidebar_position: 2
---
# ์ธ์ฆ (Authentication) vs. ์ธ๊ฐ (Authorization)
**์ธ์ฆ (Authentication)**๊ณผ **์ธ๊ฐ (Authorization)**์ ์ฐจ์ด๋ ๋ค์๊ณผ ๊ฐ์ด ์์ฝํ ์ ์์ต๋๋ค:
- **์ธ์ฆ (Authentication)**์ "์ด๋ค ์์ด๋ดํฐํฐ๋ฅผ ์์ ํ๊ณ ์์ต๋๊น?"๋ผ๋ ์ง๋ฌธ์ ๋ตํฉ๋๋ค.
- **์ธ๊ฐ (Authorization)**๋ "๋ฌด์์ ํ ์ ์์ต๋๊น?"๋ผ๋ ์ง๋ฌธ์ ๋ตํฉ๋๋ค.
๊ณ ๊ฐ ์์ด๋ดํฐํฐ ๋ฐ ์ ๊ทผ ๊ด๋ฆฌ (CIAM)์ ๋ํ ์์ ํ ์๊ฐ๋ ์ฐ๋ฆฌ์ CIAM ์๋ฆฌ์ฆ๋ฅผ ์ฐธ์กฐํ ์ ์์ต๋๋ค:
- [CIAM 101: ์ธ์ฆ (Authentication), ์์ด๋ดํฐํฐ, SSO](https://blog.logto.io/ciam-101-intro-authn-sso/)
- [CIAM 102: ์ธ๊ฐ (Authorization) & ์ญํ ๊ธฐ๋ฐ ์ ๊ทผ ์ ์ด (RBAC)](https://blog.logto.io/ciam-102-authz-and-rbac/)
## ์ธ์ฆ(Authentication) \\{#authentication}
Logto๋ ๋ค์ํ ์ํธ์์ฉ ๋ฐ ๋น์ํธ์์ฉ ์ธ์ฆ ๋ฐฉ๋ฒ์ ์ง์ํฉ๋๋ค. ์๋ฅผ ๋ค์ด:
- **๋ก๊ทธ์ธ ๊ฒฝํ**: ์ต์ข
์ฌ์ฉ์๋ฅผ ์ํ ์ธ์ฆ ๊ณผ์ .
- **๊ธฐ๊ณ ๊ฐ (M2M) ์ธ์ฆ**: ์๋น์ค ๋๋ ์ ํ๋ฆฌ์ผ์ด์
์ ์ํ ์ธ์ฆ ๊ณผ์ .
์ธ์ฆ์ ๊ถ๊ทน์ ์ธ ๋ชฉํ๋ ๋งค์ฐ ๊ฐ๋จํฉ๋๋ค: ์ํฐํฐ (Logto์์๋ ์ฌ์ฉ์ ๋๋ ์ ํ๋ฆฌ์ผ์ด์
)์ ๊ณ ์ ์๋ณ์๋ฅผ ํ์ธํ๊ณ ์ป๋ ๊ฒ์
๋๋ค.
## ๊ถํ ๋ถ์ฌ(Authorization) \\{#authorization}
Logto์์ ์ธ๊ฐ๋ ์ญํ ๊ธฐ๋ฐ ์ ๊ทผ ์ ์ด (RBAC)๋ฅผ ํตํด ์ด๋ฃจ์ด์ง๋๋ค. ์ด๋ฅผ ํตํด ์ฌ์ฉ์์ ์ ๊ทผ์ ๋ค์๊ณผ ๊ฐ์ด ์์ ํ ๊ด๋ฆฌํ ์ ์์ต๋๋ค:
- **API ๋ฆฌ์์ค**: ์ ๋ URI๋ก ํํ๋๋ ๊ธ๋ก๋ฒ ์ํฐํฐ.
- **์กฐ์ง**: ์ฌ์ฉ์ ๋๋ ์ ํ๋ฆฌ์ผ์ด์
์ ๊ทธ๋ฃน.
- **์กฐ์ง API ๋ฆฌ์์ค**: ์กฐ์ง์ ์ํ API ๋ฆฌ์์ค.
์ด ๊ฐ๋
๋ค์ ๋ํด ๋ ์๊ณ ์ถ๋ค๋ฉด ๋ค์ ๋ฆฌ์์ค๋ฅผ ์ฐธ์กฐํ์ธ์:
- [์ญํ ๊ธฐ๋ฐ ์ ๊ทผ ์ ์ด (RBAC)](/authorization/role-based-access-control)
- [์กฐ์ง (๋ค์ค ํ
๋์)](/organizations)
๋ค์์ ์ด๋ฌํ ๊ฐ๋
๋ค ๊ฐ์ ๊ด๊ณ๋ฅผ ์๊ฐ์ ์ผ๋ก ํํํ ๊ฒ์
๋๋ค:
\`\`\`mermaid
graph TD
subgraph Resources
R(API ๋ฆฌ์์ค)
O(์กฐ์ง)
OR(์กฐ์ง API ๋ฆฌ์์ค)
end
subgraph Identities
U(์ฌ์ฉ์)
A(M2M ์ ํ๋ฆฌ์ผ์ด์
)
end
\`\`\`
์์ฝํ์๋ฉด, ์ธ๊ฐ๋ "Identities" ๊ทธ๋ฃน์ ์ํฐํฐ๊ฐ "Resources" ๊ทธ๋ฃน์ ์ํฐํฐ์ ์ ๊ทผํ ์ ์๋์ง๋ฅผ ๊ฒฐ์ ํ๋ ๊ท์น์ ์ ์ํ๋ ๊ฒ์
๋๋ค.
## ์์ฃผ ๋ฌป๋ ์ง๋ฌธ \\{#frequently-asked-questions}
### ์ ํ๋ฆฌ์ผ์ด์
์ ๋ก๊ทธ์ธํ ์ ์๋ ์ฌ์ฉ์๋ฅผ ์ง์ ํด์ผ ํฉ๋๋ค \\{#i-need-to-specify-which-users-can-sign-in-to-an-application}
์ฑ๊ธ ์ฌ์ธ์จ (SSO)์ ํน์ฑ์, Logto๋ ํ์ฌ ์ ํ๋ฆฌ์ผ์ด์
์ ๋ฆฌ์์ค๋ก ์ฌ์ฉํ๋ ๊ฒ์ ์ง์ํ์ง ์์ต๋๋ค. ๋์ , API ๋ฆฌ์์ค์ ๊ถํ์ ์ ์ํ์ฌ ๋ฆฌ์์ค์ ๋ํ ์ ๊ทผ์ ์ ์ดํ ์ ์์ต๋๋ค.
### ์ฌ์ฉ์๊ฐ ์กฐ์ง์ ๋ก๊ทธ์ธํด์ผ ํฉ๋๋ค \\{#i-need-my-users-to-sign-in-to-an-organization}
์์ ์ธ๊ธํ๋ฏ์ด, ์ธ์ฆ์ ์ํฐํฐ์ ์์ด๋ดํฐํฐ๋ฅผ ํ์ธํ๋ ๊ฒ์ด๋ฉฐ, ์ ๊ทผ ์ ์ด๋ ์ธ๊ฐ๋ฅผ ํตํด ์ฒ๋ฆฌ๋ฉ๋๋ค. ๋ฐ๋ผ์:
- ์ฌ์ฉ์๊ฐ ์ํ ์กฐ์ง์ ๊ฒฐ์ ํ๋ ๊ฒ์ ์ธ๊ฐ ๋ฌธ์ ์
๋๋ค.
- ๋ก๊ทธ์ธ ๊ณผ์ ์ ์ธ์ฆ ๋ฌธ์ ์
๋๋ค.
์ด๋ Logto์์ "์กฐ์ง์ ๋ก๊ทธ์ธ"ํ๋ ๊ฐ๋
์ด ์์์ ์๋ฏธํฉ๋๋ค. ์ฌ์ฉ์๊ฐ ์ธ์ฆ๋๋ฉด, ์ ์๋ ๊ถํ์ ๋ฐ๋ผ ๋ชจ๋ ๋ฆฌ์์ค (์กฐ์ง ๋ฆฌ์์ค๋ฅผ ํฌํจ)์ ์ ๊ทผํ ์ ์๋๋ก ์ธ๊ฐ๋ ์ ์์ต๋๋ค.
์ด ๋ชจ๋ธ์ ์ธ์ฆ๊ณผ ์ธ๊ฐ์ ๋ฌธ์ ๋ฅผ ๋ถ๋ฆฌํ์ฌ ํจ์จ์ ์ด๊ณ ๋ช
ํํฉ๋๋ค. GitHub ๋ฐ Notion๊ณผ ๊ฐ์ ๋ชจ๋ ํ๋ SaaS ์ ํ๋ฆฌ์ผ์ด์
์ ์ด ๋ชจ๋ธ์ ๋ฐ๋ฆ
๋๋ค.
๊ทธ๋ฌ๋ ์ฌ์ฉ์ ์์ค์ ์กฐ์ง ๊ฐ์ 1-1 ๋งคํ์ ์ค์ ํด์ผ ํ๋ ๊ฒฝ์ฐ๊ฐ ์์ต๋๋ค. ์ด ๊ฒฝ์ฐ, [์ํฐํ๋ผ์ด์ฆ SSO](/end-user-flows/enterprise-sso) ๋ฐ [์กฐ์ง Just-in-Time (JIT) ํ๋ก๋น์ ๋](/organizations/just-in-time-provisioning)์ด ๋์์ด ๋ ์ ์์ต๋๋ค.
### ๊ณ ๊ฐ์ด ๋ก๊ทธ์ธ ํ์ด์ง์ ๋ง์ถคํ ๋ธ๋๋ฉ์ด ํ์ํฉ๋๋ค \\{#our-customers-need-custom-branding-for-their-sign-in-pages}
๊ด๋ จ ์ค์ ์ ๋ํด์๋ [์ฑ๋ณ ๋ธ๋๋ฉ](/customization/match-your-brand/#app-specific-branding) ๋ฐ [์กฐ์ง๋ณ ๋ธ๋๋ฉ](/customization/match-your-brand/#organization-specific-branding)์ ํ์ธํ์ธ์.
`,
'zh-TW': `---
sidebar_position: 2
---
# ้ฉ่ญ (Authentication) vs. ๆๆฌ (Authorization)
**้ฉ่ญ (Authentication)** ่ **ๆๆฌ (Authorization)** ็ๅทฎ็ฐๅฏ็ฐก่ฟฐๅฆไธ๏ผ
- **้ฉ่ญ (Authentication)** ๅ็ญใไฝ ๆๆๅชๅ่บซๅ๏ผใ
- **ๆๆฌ (Authorization)** ๅ็ญใไฝ ๅฏไปฅๅท่กๅชไบๆไฝ๏ผใ
ๅฎๆด็ๅฎขๆถ่บซๅ่ๅญๅ็ฎก็๏ผCIAM, Customer Identity and Access Management๏ผไป็ดน๏ผ่ซๅ้ฑๆๅ็ CIAM ็ณปๅๆ็ซ ๏ผ
- [CIAM 101๏ผ้ฉ่ญ (Authentication)ใ่บซๅ (Identity) ่ๅฎไธ็ปๅ
ฅ (SSO, Single Sign-On)](https://blog.logto.io/ciam-101-intro-authn-sso/)
- [CIAM 102๏ผๆๆฌ (Authorization) ่่ง่ฒๅๅญๅๆงๅถ (RBAC, Role-based Access Control)](https://blog.logto.io/ciam-102-authz-and-rbac/)
## ้ฉ่ญ (Authentication) \\{#authentication}
Logto ๆฏๆดๅค็จฎไบๅๅผ่้ไบๅๅผ้ฉ่ญๆนๆณ๏ผไพๅฆ๏ผ
- **็ปๅ
ฅ้ซ้ฉ (Sign-in experience)**๏ผ็ต็ซฏไฝฟ็จ่
็้ฉ่ญๆต็จใ
- **ๆฉๅจๅฐๆฉๅจ้ฉ่ญ (M2M, Machine-to-Machine authentication)**๏ผๆๅๆๆ็จ็จๅผ็้ฉ่ญๆต็จใ
้ฉ่ญ็ๆ็ต็ฎๆจๆฅต็บ็ฐกๅฎ๏ผ้ฉ่ญไธฆๅๅพๅฏฆ้ซ๏ผๅจ Logto ไธญๅณไฝฟ็จ่
ๆๆ็จ็จๅผ๏ผ็ๅฏไธ่ญๅฅ็ฌฆใ
## ๆๆฌ (Authorization) \\{#authorization}
ๅจ Logto ไธญ๏ผๆๆฌ้้ **่ง่ฒๅๅญๅๆงๅถ (RBAC, Role-based Access Control)** ๅฏฆ็พ๏ผ่ฎไฝ ๅฎๆดๆงๅถไฝฟ็จ่
ๆ M2M ๆ็จ็จๅผๅฐไปฅไธ้
็ฎ็ๅญๅๆฌ้๏ผ
- **API ่ณๆบ (API resources)**๏ผไปฅ็ตๅฐ URI ่กจ็คบ็ๅ
จๅฑๅฏฆ้ซใ
- **็ต็น (Organizations)**๏ผไฝฟ็จ่
ๆๆ็จ็จๅผ็็พค็ตใ
- **็ต็น API ่ณๆบ (Organization API resources)**๏ผๅฑฌๆผ็นๅฎ็ต็น็ API ่ณๆบใ
ๆทฑๅ
ฅ็ญ่งฃ้ไบๆฆๅฟต๏ผ่ซๅ้ฑ๏ผ
- [่ง่ฒๅๅญๅๆงๅถ (RBAC)](/authorization/role-based-access-control)
- [็ต็น๏ผๅค็งๆถ๏ผMulti-tenancy๏ผ](/organizations)
ไปฅไธๅ่กจ็ด่งๅ็พ้ไบๆฆๅฟต้็้ไฟ๏ผ
\`\`\`mermaid
graph TD
subgraph Resources
R(API ่ณๆบ (API resources))
O(็ต็น (Organizations))
OR(็ต็น API ่ณๆบ (Organization API resources))
end
subgraph Identities
U(ไฝฟ็จ่
(Users))
A(M2M ๆ็จ็จๅผ (M2M applications))
end
\`\`\`
็ฐก่่จไน๏ผๆๆฌๆฏๅฎ็พฉ่ฆๅไพๆฑบๅฎใ่บซๅ (Identities)ใ็พค็ตไธญ็ๅฏฆ้ซ่ฝๅญๅใ่ณๆบ (Resources)ใ็พค็ตไธญ็ๅชไบๅฏฆ้ซใ
## ๅธธ่ฆๅ้ก \\{#frequently-asked-questions}
### ๆ้่ฆๆๅฎๅชไบไฝฟ็จ่
่ฝ็ปๅ
ฅๆ็จ็จๅผ \\{#i-need-to-specify-which-users-can-sign-in-to-an-application}
็ฑๆผๅฎไธ็ปๅ
ฅ (SSO, Single Sign-On) ็็นๆง๏ผLogto ็ฎๅไธๆฏๆดๅฐๆ็จ็จๅผไฝ็บ่ณๆบใๅปบ่ญฐๆน็บๅฎ็พฉ API ่ณๆบ่ๆฌ้ไพๆงๅถ่ณๆบๅญๅใ
### ๆ้่ฆไฝฟ็จ่
็ปๅ
ฅ็ต็น \\{#i-need-my-users-to-sign-in-to-an-organization}
ๅฆๅๆ่ฟฐ๏ผ้ฉ่ญๆถๅ็ขบ่ชๅฏฆ้ซ่บซๅ๏ผ่ๅญๅๆงๅถ้้ๆๆฌ่็ใๅ ๆญค๏ผ
- ๅคๆทไฝฟ็จ่
ๆๅฑฌ็ต็นๅฑฌๆผๆๆฌ็ฏ็ใ
- ็ปๅ
ฅๆต็จๅฑฌๆผ้ฉ่ญ็ฏ็ใ
้่กจ็คบ Logto ไธญไธๅญๅจใ็ปๅ
ฅ็ต็นใ็ๆฆๅฟตใไฝฟ็จ่
้ฉ่ญๅพ๏ผๅณๅฏๆ นๆๅฎ็พฉ็ๆฌ้ๅญๅๆๆ่ณๆบ๏ผๅ
ๅซ็ต็น่ณๆบ๏ผใ
ๆญคๆจกๅ้ซๆไธๆธ
ๆฐ๏ผๅ้ขไบ้ฉ่ญ่ๆๆฌ็้ๆณจ้ปใๆๆ็พไปฃ SaaS ๆ็จ็จๅผ๏ผๅฆ GitHub ๅ Notion๏ผๅ้ตๅพชๆญคๆจกๅใ
่ฅ้ๅปบ็ซไฝฟ็จ่
ไพๆบ่็ต็น็ 1-1 ๅฐๆ๏ผๅฏๅ่ [ไผๆฅญ็ดๅฎไธ็ปๅ
ฅ (Enterprise SSO)](/end-user-flows/enterprise-sso) ๅ [็ต็นๅณๆไฝๅปบ (JIT, Just-in-Time provisioning)](/organizations/just-in-time-provisioning)ใ
### ๅฎขๆถ้่ฆ่ช่จ็ปๅ
ฅ้ ้ขๅ็ \\{#our-customers-need-custom-branding-for-their-sign-in-pages}
่ซๅ้ฑ [ๆ็จ็จๅผๅฐๅฑฌๅ็่จญๅฎ (App-specific branding)](/customization/match-your-brand/#app-specific-branding) ๅ [็ต็นๅฐๅฑฌๅ็่จญๅฎ (Organization-specific branding)](/customization/match-your-brand/#organization-specific-branding) ้ฒ่ก็ธ้้
็ฝฎใ
`,
});
/* eslint-enable max-lines */