FDE Foundations · Module 11: Security & Data

Authorization Basics

Authorization fails at the edges: endpoints that forgot the check, objects referenced by ID, admin routes hidden in the UI. Model it explicitly, enforce everywhere, test the negatives.

11 min reading

Objectives

  • Model roles and permissions explicitly
  • Enforce authorization server-side on every request
  • Test the negative cases as first-class citizens

Explicit model

Write down roles, what each may do, and on which objects (own, team, org). Keep the model small: role proliferation is a security smell. If the customer has an existing identity provider, integrate with its groups rather than inventing a parallel universe.

Enforce everywhere, server-side

The check lives in the server for every request, including list endpoints (filter by permission), nested resources, and exports. The UI hiding a button is cosmetics, not enforcement. Object-level checks matter most: user A fetching user B's invoice by changing the ID is the classic vulnerability, and it is caught only by testing IDs you do not own.

Deny by default

New endpoints start closed: an undeclared route rejects, a missing role check fails a lint rule if you can encode one. Default-open systems rot: every new feature silently skips the step nobody remembers.

Negative tests

For every endpoint, write the test where access must fail. The suite of "no" cases is your regression net, and it doubles as documentation of the model. Include expired sessions, deactivated users, and cross-tenant probes in the set.

Quick check

An optional 2-3 question self-check. Answers never leave your device, are not stored, and never count toward any assessment.

Exercise

Write the authorization model for a fictional billing portal: three roles with permissions on two object types, the server-side enforcement points, and five negative tests you would write.

Pass criteria

Model is explicit and small, enforcement includes object-level checks and list filtering, and the five negative tests cover ID manipulation and expired or deactivated identities.

Log in to track progressFree account: stores only your lesson progress and quiz results.

We use Google Analytics to count visits. No ads, no cross-site tracking. Cookie Policy