Knowledgebase

Authorisation and Permissions in APIs Print

  • 0

What a caller may do.

WHAT AUTHORISATION ANSWERS

Whether this caller may perform this action on this object.

WHY IT IS SEPARATE FROM AUTHENTICATION

Knowing who someone is says nothing about what they may do.

WHAT THE COMMONEST SERIOUS FAULT IS

Checking who the caller is, and not whether the object belongs to them.

WHAT THAT PERMITS

Changing an identifier in a request and reading someone else's data.

HOW TO TEST FOR IT

Authenticate as one account and request another's records.

WHAT TO AUTOMATE

That test, across every endpoint.

WHY AUTOMATE

The surface grows with every feature.

WHAT TO ENFORCE

The ownership check inside the data layer, not in each handler.

WHY

One forgotten handler is a breach.

WHAT ROLE-BASED PERMISSIONS PROVIDE

Actions granted to roles, roles granted to callers.

WHAT SCOPE-BASED PERMISSIONS PROVIDE

Limits attached to the token itself.

WHAT TO COMBINE

Both: the scope limits the token, the role limits the account.

WHAT TO RETURN WHEN SOMETHING EXISTS BUT IS NOT PERMITTED

Consider not-found rather than forbidden.

WHY

Forbidden confirms the object exists, which leaks information.

WHAT TO LOG

Denied attempts.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot