A bulk export still needs per-row authorization
Export and “download all” endpoints are where object-level checks quietly disappear. The UI shows a filtered table, but the export handler often runs a privileged query, streams every matching id, and trusts that the list page already did the hard part. If any row in that stream would 404 or 403 on the single-resource path, the export just became a bulk BOLA. Patterns that hold up: Authorize the action (can this subject export this collection?) and then constrain the query with the same scope the list API uses — tenant, ownership, relationship — not a god-mode SELECT * WHERE created_at …. Pref
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in