FDE Foundations · Module 11: Security & Data
Authorization Basics
Authorization fails at the edges: endpoints that forgot the check, objects referenced by ID, admin routes hidden in the UI. Model it explicitly, enforce everywhere, test the negatives.
11 min reading
Objectives
- Model roles and permissions explicitly
- Enforce authorization server-side on every request
- Test the negative cases as first-class citizens
Explicit model
Write down roles, what each may do, and on which objects (own, team, org). Keep the model small: role proliferation is a security smell. If the customer has an existing identity provider, integrate with its groups rather than inventing a parallel universe.
Enforce everywhere, server-side
The check lives in the server for every request, including list endpoints (filter by permission), nested resources, and exports. The UI hiding a button is cosmetics, not enforcement. Object-level checks matter most: user A fetching user B's invoice by changing the ID is the classic vulnerability, and it is caught only by testing IDs you do not own.
Deny by default
New endpoints start closed: an undeclared route rejects, a missing role check fails a lint rule if you can encode one. Default-open systems rot: every new feature silently skips the step nobody remembers.
Negative tests
For every endpoint, write the test where access must fail. The suite of "no" cases is your regression net, and it doubles as documentation of the model. Include expired sessions, deactivated users, and cross-tenant probes in the set.
Quick check
An optional 2-3 question self-check. Answers never leave your device, are not stored, and never count toward any assessment.
Exercise
Write the authorization model for a fictional billing portal: three roles with permissions on two object types, the server-side enforcement points, and five negative tests you would write.
Pass criteria
Model is explicit and small, enforcement includes object-level checks and list filtering, and the five negative tests cover ID manipulation and expired or deactivated identities.