SShortSingh.
Back to feed

A bulk export still needs per-row authorization

0
·1 views

Export and “download all” endpoints are where object-level checks quietly disappear. The UI shows a filtered table, but the export handler often runs a privileged query, streams every matching id, and trusts that the list page already did the hard part. If any row in that stream would 404 or 403 on the single-resource path, the export just became a bulk BOLA. Patterns that hold up: Authorize the action (can this subject export this collection?) and then constrain the query with the same scope the list API uses — tenant, ownership, relationship — not a god-mode SELECT * WHERE created_at …. Pref

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Espacenet Ops: A Scalable Global Patent Search Model

A scalable Espacenet ops framework runs on four sequential stages: Retrieve, Align, Invalidate-check, and Ledger. It is measured by auditable recall per jurisdiction per dollar, not by the number of databases a tool claims to touch. One variable separates a defensible search operation from an expensive one: time-to-defensible-output, not feature count. Everything below maps that principle to concrete workflow architecture, quantitative scoring, failure-mode reconciliation, and a procurement-grade comparison matrix. This is written for people who already run multi-jurisdiction searches: Head of

0
ProgrammingDEV Community ·

Building a Dynamic Strategy Pattern in C# with Customer Tiers and Plugin Architecture

The Strategy Pattern is a staple of object-oriented design. It lets you encapsulate a family of algorithms and make them interchangeable at runtime. However, traditional implementations often suffer from heavy interface hierarchies and rigid factory logic. In modern C#, language features like switch expressions, primary constructors, collection expressions, and collectible AssemblyLoadContext allow us to build clean, extensible strategy pipelines with zero unnecessary boilerplate. In this article, we'll walk through building a flexible shipping rate calculator that supports: Multiple Carrier S

0
ProgrammingDEV Community ·

A listing id that ignores the query string, and the trailing slash that would have made every room new

Notifio is a desktop app that watches rental search result pages and tells you the moment a new listing appears on one. The whole product is a diff. It reads a search page, compares what is on it with what was on it last time, and the difference is the alert. Which means the only interesting question in the codebase is what counts as "the same listing". Get that wrong in one direction and the user gets an email about a room they already replied to.