DEV Community

Auth By Example
Auth By Example

Posted on

Your CSV export can include rows the list already hid

List pages usually filter by tenant and role before they render rows. Export endpoints often take a different path. The table shows forty invoices the caller can see. Export CSV hits /invoices/export with a pile of ids from the client, or with the same filters copied into a second query that dropped the tenant clause during a refactor.

Either way the file can hold invoices from another org, or rows the user lost access to since they loaded the page.

Run the export through the same authorization filter as the list. Prefer filtering on the server over trusting ids from the browser. If export is async, check access again when the job runs, not only when someone clicked the button.

Top comments (0)