CHAPTER 11 · Security, Auth, and Multi-Tenancy · 3 / 9
Authorization: centralize it
Authorization is where agents most often go wrong, because there are many routes and each touches resources. The discipline:
- Centralize the checks. Put the "can this user access this project/document/resource?" logic in a small, audited set of helper functions, and call them at the top of every route. Don't re-implement the ownership/sharing join in each handler; that's how one handler ends up missing a check.
- Model permission explicitly. Owner vs. shared-member vs. no-access. Return enough detail (e.g. an
isOwnerflag) to gate owner-only operations (delete, rename, manage members) separately from read/write. - Check the resource, not just the route. "User is logged in" is not "user may edit document X." Load the resource, evaluate access against it.
- Guard list/batch inputs. When a request supplies a list of resource ids (e.g. "extract from these documents"), filter that list down to the ones the caller may actually access before acting. Otherwise a user can smuggle ids they shouldn't reach.