DEV Community

Auth By Example
Auth By Example

Posted on

A list endpoint must filter by authorization

Protecting GET /invoices/:id is not enough if GET /invoices returns every tenant's rows.

Detail routes catch object-level mistakes. List and search routes leak by volume. Apply the same authorization predicate—tenant, ownership, role scope—when you query the collection, not only when you fetch one record.

Authorization is a filter on every read path, not a gate on the detail page only.

Top comments (0)