DEV Community

Auth By Example
Auth By Example

Posted on

Duplicating a record should check access to everything it copies

"Duplicate project" is a handy button. The handler usually checks that the caller can read the project, then copies the project row and everything hanging off it: tasks, attachments, linked documents, saved filters.

The children don't always share the parent's permissions, though. A private task inside a shared project, or a document linked in from another workspace, gets copied into a new project the caller owns. Now they can read it.

What I'd do:

  • Run the read check on each child you copy, with the caller as the user. Leave out the ones that fail and tell the caller some items were skipped.
  • Copy references to other workspaces as links, so opening them still goes through the normal check.
  • Templates and "save as template" usually share this code path. Check them too.
  • Add a test: user A duplicates a project that contains a task only user B can see. The copy should not contain that task.

If you want every route to call one shared decision function, this write-up on splitting enforcement from the decision (PEP/PDP) covers the pattern. Disclosure: I work with Permit.io.

Top comments (0)