Authorization or authentication

I don’t understand your question. Are you asking about security risks of using authorization in general, or using authorization to do more than just authorize? Or are you asking something else entirely different?