DEV Community

Auth By Example
Auth By Example

Posted on

A batch API is not a free pass on every item

Batch and bulk endpoints are convenient: one request, many IDs. They are also a classic place where authorization shrinks to "caller can hit this route."

If your handler loads ten resources and returns whatever the IDs resolve to, a caller who is allowed to see one row can often learn about nine others. The same trap shows up on bulk update, delete, and "export these records" paths.

Authorize every item in the batch against the current subject, tenant, and action. Fail closed on any ID the caller must not touch — do not silently skip it and keep returning the rest unless that behavior is an explicit, audited product choice.

A route-level role check is necessary. Per-item authorization is what makes a batch API safe.

Top comments (0)