ABAuth By Exampleinauthbyexample.hashnode.dev·34m ago · 2 min readYour permission cache key needs the tenant in itA common speedup is caching the answer to "can this user do this action" for a minute or two. The trouble starts when the cache key is only user ID plus action. Someone who belongs to two workspaces g00
ABAuth By Exampleinauthbyexample.hashnode.dev·5h ago · 1 min readDeactivating a user should shut off their API tokens tooWhen someone leaves, an admin marks their account deactivated and the login page starts rejecting them. Their personal API tokens often keep working anyway. The token middleware looks up the token has00
SMSatyajit Mishrainblogs.satyajitmishra.me·21h ago · 8 min readSpring Security Explained: Understanding Authentication, JWT, and OAuth2 from the Inside OutSpring Security Explained: What Really Happens Behind Every Login Request? When I first started learning Spring Security, I was overwhelmed by terms like Security Filter Chain, Authentication Manager,00
ZZyVOPinblog.zyvop.com·20h ago · 13 min readCASL: One Set of Permission Rules for Your Whole JavaScript AppMost apps start with a line like if (user.role === 'admin'). Then the same check shows up in a React component, then in an API handler, then in a database query. Six months later nobody remembers whic42A
ABAuth By Exampleinauthbyexample.hashnode.dev·1d ago · 1 min readAn API key shouldn't carry its creator's whole roleA lot of apps let a user click "create API key" and the key quietly gets everything that user can do. If the user is an admin, the key is an admin key. It ends up in a CI secret or a teammate's script00
ABAuth By Exampleinauthbyexample.hashnode.dev·1d ago · 1 min readAssigning a task should check that the assignee can see itMost "assign" endpoints check one thing: can the caller edit this task? If yes, PATCH /tasks/88 {"assignee_id": 512} goes through. Nobody asks whether user 512 can see task 88. In a multi-tenant app t00
ABAuth By Exampleinauthbyexample.hashnode.dev·2d ago · 2 min readEditing a comment needs an author check, tooA user can open a shared ticket, so the comment API lets them through. The edit endpoint loads the comment by ID, checks that the caller can read the parent ticket, and saves the new text. Now anyone 02I
ABAuth By Exampleinauthbyexample.hashnode.dev·1d ago · 2 min readAn activity feed needs the same access check as the records it mentionsMost apps add an activity feed after the core screens are done: "Dana moved Q3 pricing review to Done." It usually reads from one events table filtered by workspace or project, and nobody ties it back00
ABAuth By Exampleinauthbyexample.hashnode.dev·3d ago · 2 min readYour search index is a second copy of your data, so it needs the same permissionsA common pattern: the app checks permissions carefully on every detail page, then adds search later. Documents, tickets or messages get pushed into a search index, and the search endpoint returns what02I
OFOluwaseyi Fatunmoleinfreecodecamp.org·2d ago · 22 min readAPI Authentication & Authorization: An Engineering Deep Dive into Mechanisms, Trade-offs, and Failure ModesEvery API has some form of authentication. But having authentication and getting it right are two completely different things. I've reviewed production systems where JWTs had no expiry. Systems where 00