Skip to slide
Chapter 11 · Security, Auth, and Multi-Tenancy
101 / 191

CHAPTER 11 · Security, Auth, and Multi-Tenancy · 3 / 9

Authorization: centralize it

Authorization is where agents most often go wrong, because there are many routes and each touches resources. The discipline:

  • Centralize the checks. Put the "can this user access this project/document/resource?" logic in a small, audited set of helper functions, and call them at the top of every route. Don't re-implement the ownership/sharing join in each handler; that's how one handler ends up missing a check.
  • Model permission explicitly. Owner vs. shared-member vs. no-access. Return enough detail (e.g. an isOwner flag) to gate owner-only operations (delete, rename, manage members) separately from read/write.
  • Check the resource, not just the route. "User is logged in" is not "user may edit document X." Load the resource, evaluate access against it.
  • Guard list/batch inputs. When a request supplies a list of resource ids (e.g. "extract from these documents"), filter that list down to the ones the caller may actually access before acting. Otherwise a user can smuggle ids they shouldn't reach.
← → arrow keys work too