← REST APIs: integrate applications and diagnose failures
04 / 6 · 40 MIN

Authorization and boundaries

Evaluate subject, operation, and object on every access.

Concept and mechanism

Authenticating a caller does not grant access to every object. Authorization must connect identity, action, resource, and tenant context. A hard-to-guess identifier reduces casual discovery but does not replace an access decision. Also validate functions: someone allowed to read a request does not automatically gain permission to approve it or export the entire portfolio. A path name and a hidden interface button do not enforce that restriction on the server. Define tests with subjects and objects from different scopes, using fictional data and environments intended for validation.

Guided application

In a fictional APS example, a token valid for reporting reaches the change service. Checking its signature is insufficient if intended audience does not match the resource. Even a suitable token remains subject to operation and object permissions. In a browser, CORS determines when a response can be shared with code from another origin; it does not replace API authorization. A credentialed request cannot use a wildcard allowed origin in that flow. If the browser fails while a backend client works, investigate origin, preflight, headers, and credentials before concluding the API is unavailable. Keep diagnosis free of printed tokens.

IN PRACTICE

Reading an object and approving it require their own authorization decisions even with the same token.

Common pitfalls

UUID as authorization; signature as correct audience; CORS as universal access control; interface as enforcement.

Related topics: API resources and contracts · Requests and outcomes · Concurrency and retries

Take this idea with you

Enforce policy on the server and distinguish it from browser controls.

Create account

Reference: API1:2023 Broken Object Level Authorization · HTTP semantics RFC9110; OpenAPI3.2.1; selected primary standards and provider contracts consulted2026-09-30