Queue workers and background jobs often inherit a user id, a tenant id, or a token snapshot from the request that enqueued them. That snapshot is not a standing grant.
By the time the job runs, the membership may have been revoked, the role narrowed, or the resource moved. If the worker only checks "this job was queued by someone who was allowed," it can act with privileges the subject no longer has.
Re-authorize in the job against the current subject, tenant, and action before every sensitive read or write. Treat the enqueue-time check as a filter on what may be scheduled, not as permission to finish the work later.
Async is a delivery mechanism. Authorization still belongs at the moment of access.
Top comments (0)