A signed cookie is not object authorization
Signed cookies are great for integrity: the browser cannot silently rewrite a payload you sealed with a server secret. That still does not decide which objects the user may touch. Teams often stuff a user id, a role, or even a tenant id into a signed cookie and then treat “signature valid” as “request authorized.” The cookie only proves the blob was minted by you. It does not prove the caller may read invoice #4821, mutate another user’s project, or act across tenants. What to do instead: Authenticate the session (cookie, token, whatever) to learn who is calling.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in