Protecting GET /invoices/:id is not enough if GET /invoices returns every tenant's rows.
Detail routes catch object-level mistakes. List and search routes leak by volume. Apply the same authorization predicate—tenant, ownership, role scope—when you query the collection, not only when you fetch one record.
Authorization is a filter on every read path, not a gate on the detail page only.
Top comments (0)