DEV Community

Auth By Example
Auth By Example

Posted on Originally published at permit.io

Four questions to ask about one real authorization flow

A lot of authorization trouble has nothing to do with missing roles. The check exists somewhere, just not at the action that matters, or it runs on data that went stale an hour ago.

Try this on one flow that can actually hurt you, like inviting a user, exporting a report, or an agent calling a tool.

  1. Does the action itself ask for a decision? A role check at login or on the route won't cover the list query that forgets to filter by tenant.
  2. Does the decision know enough? user.role == "admin" ignores tenant scope, ownership and resource state. You want something closer to "can subject U do action A on resource R in tenant T right now?"
  3. How long does a revoke take? If a removed user keeps export access until a 30-minute cache expires, decide whether that's fine for that action. For a UI hint, maybe. For a data export, probably not.
  4. Can you explain the result later? A log line that says 403 won't tell anyone which policy decided or why.

Disclosure: I work at Permit.io. We wrote up these four areas (enforcement, granularity, realtime, audit) and the architecture that connects them:

https://www.permit.io/blog/enforcement-granularity-realtime-audit?utm_source=devto&utm_medium=social&utm_campaign=enforcement-granularity-realtime-audit&utm_content=authbyexample-article

Top comments (0)