What a caller may do.
WHAT AUTHORISATION ANSWERS
Whether this caller may perform this action on this object.
WHY IT IS SEPARATE FROM AUTHENTICATION
Knowing who someone is says nothing about what they may do.
WHAT THE COMMONEST SERIOUS FAULT IS
Checking who the caller is, and not whether the object belongs to them.
WHAT THAT PERMITS
Changing an identifier in a request and reading someone else's data.
HOW TO TEST FOR IT
Authenticate as one account and request another's records.
WHAT TO AUTOMATE
That test, across every endpoint.
WHY AUTOMATE
The surface grows with every feature.
WHAT TO ENFORCE
The ownership check inside the data layer, not in each handler.
WHY
One forgotten handler is a breach.
WHAT ROLE-BASED PERMISSIONS PROVIDE
Actions granted to roles, roles granted to callers.
WHAT SCOPE-BASED PERMISSIONS PROVIDE
Limits attached to the token itself.
WHAT TO COMBINE
Both: the scope limits the token, the role limits the account.
WHAT TO RETURN WHEN SOMETHING EXISTS BUT IS NOT PERMITTED
Consider not-found rather than forbidden.
WHY
Forbidden confirms the object exists, which leaks information.
WHAT TO LOG
Denied attempts.