DEV Community

Auth By Example
Auth By Example

Posted on

A nested resource path still needs two authorization checks

APIs love nested routes: /orgs/{orgId}/invoices/{invoiceId}, /projects/{projectId}/files/{fileId}. A common bug is authorizing only the leaf.

You load the invoice by invoiceId, confirm the caller is authenticated, and return it. That skips whether this invoice belongs to orgId, and whether the caller may access that org at all. Guessable or leaked leaf IDs become a BOLA finding even when the path "looks" scoped.

Authorize the parent first (membership / tenant / project access), then authorize the child in that parent's context (object ownership or relationship). Prefer loading the child with a query that includes the parent key so a cross-parent ID fails closed.

Path shape is documentation, not a policy. Subject + action + parent + child still has to win at the moment of access.

Top comments (0)