Batch APIs need per-item authorization, not just route-level access checks
Batch and bulk API endpoints allow a single request to fetch or modify multiple resources at once, but this convenience can introduce serious authorization gaps. If access control is only enforced at the route level, a caller permitted to view one record may inadvertently gain access to many others in the same batch. This vulnerability extends to bulk update, delete, and data export operations. Security best practice requires that every item in a batch be individually authorized against the current user, tenant, and action type. Any item the caller is not permitted to access should trigger a hard failure rather than being silently skipped.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in