Background Jobs Must Re-Authorize at Runtime, Not Just at Enqueue Time
Async background jobs commonly inherit user IDs, tenant IDs, or token snapshots from the original request that scheduled them. However, these snapshots do not constitute a permanent permission grant, as roles, memberships, or resource access may change before the job actually executes. A worker that relies solely on enqueue-time credentials risks acting with privileges the user no longer holds. Developers should re-authorize each job against the current subject, tenant, and action immediately before any sensitive read or write operation. The enqueue-time check should only determine what can be scheduled, while final authorization must occur at the actual moment of data access.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in