Access control

Access control (authorization) answers whether a caller is allowed to perform an action on data. Failures are common and high impact. Organize testing and documentation by where the check fails:

SubtopicQuestion
Endpoint levelIs this route or function restricted to the right roles or tenants?
Object levelMay this user access this specific record (IDs, slugs, nested resources)?
Property levelCan the user change fields they should not (mass assignment, partial updates)?
Trust boundaryDoes the app believe headers, client certificates, or upstream identity without sound binding?

Cookie Consent

We use cookies to enhance your experience. Learn more