A trusted identity header is not an authorization decision
A reverse proxy or API gateway can inject X-User-Id, X-Forwarded-User, or a custom “trusted” identity header after authenticating at the edge. That header answers who the request claims to be. It does
authbyexample.hashnode.dev3 min read