DEV Community

Auth By Example
Auth By Example

Posted on

An admin shouldn't be able to grant a role bigger than their own

Most role-assignment endpoints check one thing: can the caller manage members? If yes, whatever role is in the request body goes through.

So a project admin sends PATCH /members/42 {"role": "owner"} with their own user ID, or a friend's, and now they hold permissions nobody gave them. The UI dropdown hid "owner". The API never did.

Two checks cover most of it:

  • The caller can only assign roles whose permissions are a subset of their own on that same resource.
  • The caller can't raise their own role. Someone with a higher role has to do that.

To test it, sign in with the lowest role that can manage members and call the endpoint directly with every role name your system has, including the ones that never show up in the dropdown. Anything above the caller's own level should come back 403.

If you want a refresher on how roles and permissions fit together, Permit.io has a short write-up (we're affiliated): What is RBAC?

Top comments (0)