DEV Community

Auth By Example
Auth By Example

Posted on

A report that joins tables can leak rows your list pages would hide

List endpoints usually filter by tenant and role. Reports often skip that. Someone builds a revenue report that joins orders to customers and territories, then runs a raw SQL query or an ORM join with no per-table access filter.

A sales rep who can only see their own territory still gets totals that include every order the join touches. Sometimes the detail rows are filtered and the summary cards are not, so the number on the dashboard is bigger than anything they can open.

Apply the same access filter each list endpoint uses to every table in the join, before you aggregate. If the rep cannot read an order, it should not count toward their report either.

Quick test: seed two territories, give a user access to only one, and run the report. The totals and the row count should match what their order list returns for the same filters.

Top comments (0)