DEV Community

Auth By Example profile picture

Auth By Example

Practical lessons on auth, authorization, and access control.

Joined Joined on  Personal website https://www.permit.io
What EU AI Act Article 12 and ISO 42001 mean for AI agent logs

What EU AI Act Article 12 and ISO 42001 mean for AI agent logs

Comments
2 min read

Want to connect with Auth By Example?

Create an account to connect with Auth By Example. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
GraphQL resolvers often check the top-level object and skip the nested ones

GraphQL resolvers often check the top-level object and skip the nested ones

Comments 2
1 min read
The user picker in your share dialog can leak your whole user table

The user picker in your share dialog can leak your whole user table

Comments
1 min read
An admin shouldn't be able to grant a role bigger than their own

An admin shouldn't be able to grant a role bigger than their own

Comments
1 min read
Archiving a workspace should make the API read-only too

Archiving a workspace should make the API read-only too

Comments
1 min read
Four questions to ask about one real authorization flow

Four questions to ask about one real authorization flow

Comments
1 min read
Duplicating a record should check access to everything it copies

Duplicating a record should check access to everything it copies

Comments
1 min read
Attachment downloads should check the record they belong to

Attachment downloads should check the record they belong to

Comments
1 min read
Counts and totals need the same authorization filter as the list

Counts and totals need the same authorization filter as the list

Comments 2
1 min read
A valid token is not an AI agent audit trail

A valid token is not an AI agent audit trail

Comments
1 min read
An email domain is not tenant membership

An email domain is not tenant membership

Comments
2 min read
A presigned URL is not ongoing authorization

A presigned URL is not ongoing authorization

Comments
2 min read
An MFA challenge pass is not object authorization

An MFA challenge pass is not object authorization

Comments
1 min read
A CORS allowlist is not authorization

A CORS allowlist is not authorization

Comments
1 min read
A signed cookie is not object authorization

A signed cookie is not object authorization

Comments
1 min read
A reverse-proxy auth plugin is not application authorization

A reverse-proxy auth plugin is not application authorization

Comments
1 min read
A shared service account is not per-tenant authorization

A shared service account is not per-tenant authorization

Comments
1 min read
A system cron job still needs per-tenant authorization

A system cron job still needs per-tenant authorization

1
Comments 5
1 min read
Stop picking an authorization religion

Stop picking an authorization religion

Comments
1 min read
Tool traces are not an AI agent audit trail

Tool traces are not an AI agent audit trail

Comments
1 min read
A bulk export still needs per-row authorization

A bulk export still needs per-row authorization

Comments
1 min read
An alternate-key lookup still needs object authorization

An alternate-key lookup still needs object authorization

Comments
1 min read
IdP login logs cannot answer "why was this allowed?"

IdP login logs cannot answer "why was this allowed?"

Comments
1 min read
A client-supplied tenant id is not authorization

A client-supplied tenant id is not authorization

Comments 2
1 min read
SOC 2 CC6 and ISO 27001 still assume humans — agents break the evidence model

SOC 2 CC6 and ISO 27001 still assume humans — agents break the evidence model

Comments
1 min read
A nested resource path still needs two authorization checks

A nested resource path still needs two authorization checks

Comments
1 min read
A long-lived stream is not a standing permission grant

A long-lived stream is not a standing permission grant

Comments 1
1 min read
IdP login logs are not enough for SOC 2-style access reviews

IdP login logs are not enough for SOC 2-style access reviews

Comments
1 min read
An async job is not a free pass on authorization

An async job is not a free pass on authorization

Comments
1 min read
Login events are not authorization evidence

Login events are not authorization evidence

Comments
1 min read
A batch API is not a free pass on every item

A batch API is not a free pass on every item

Comments
1 min read
A WebSocket reconnect is not a free pass

A WebSocket reconnect is not a free pass

2
Comments 1
1 min read
What least-privilege evidence your authz model can actually produce

What least-privilege evidence your authz model can actually produce

1
Comments 3
1 min read
A valid webhook signature is not authorization

A valid webhook signature is not authorization

2
Comments 2
1 min read
Feature Flags Are Not Authorization

Feature Flags Are Not Authorization

Comments
2 min read
When every exception becomes a new role, you need attributes

When every exception becomes a new role, you need attributes

Comments
1 min read
AI agents that inherit your OAuth token break least privilege

AI agents that inherit your OAuth token break least privilege

Comments 1
1 min read
A share link is a scoped grant, not permanent access

A share link is a scoped grant, not permanent access

Comments
1 min read
Search results still need authorization filters

Search results still need authorization filters

Comments
1 min read
A list endpoint must filter by authorization

A list endpoint must filter by authorization

Comments
1 min read
Email verified is not authorization

Email verified is not authorization

1
Comments
1 min read
Rate limiting is not authorization

Rate limiting is not authorization

Comments
1 min read
WebSocket subscribe is still authorization

WebSocket subscribe is still authorization

Comments 1
1 min read
MFA is not authorization

MFA is not authorization

Comments
1 min read
CORS is not authorization

CORS is not authorization

1
Comments
1 min read
Background jobs still need the caller's authorization

Background jobs still need the caller's authorization

Comments
1 min read
OAuth scopes are not object permissions

OAuth scopes are not object permissions

Comments
1 min read
Frontend visibility is not authorization

Frontend visibility is not authorization

Comments
1 min read
Service identity is not user permission

Service identity is not user permission

Comments
1 min read
A tenant claim is not tenant isolation

A tenant claim is not tenant isolation

Comments
1 min read
OAuth on MCP is not the same as authorizing each tool call

OAuth on MCP is not the same as authorizing each tool call

Comments
1 min read
Project access is not object permission

Project access is not object permission

Comments
1 min read
A stale authorization cache is not a current permission

A stale authorization cache is not a current permission

Comments
1 min read
Feature flags are not authorization

Feature flags are not authorization

Comments
1 min read
Tenant membership is not resource permission

Tenant membership is not resource permission

Comments
1 min read
Read permission is not export permission

Read permission is not export permission

Comments
1 min read
Page 2 of a list still needs the same authorization filter

Page 2 of a list still needs the same authorization filter

Comments 4
1 min read
mTLS proves which service called you — not what it may do

mTLS proves which service called you — not what it may do

Comments
1 min read
OAuth scopes are not your app's authorization model

OAuth scopes are not your app's authorization model

Comments 1
1 min read
Creating a child resource still needs a check on the parent

Creating a child resource still needs a check on the parent

Comments
1 min read
loading...