DEV Community

Auth By Example profile picture

Auth By Example

Practical lessons on auth, authorization, and access control.

Joined Joined on  Personal website https://www.permit.io
AI agents that inherit your OAuth token break least privilege

AI agents that inherit your OAuth token break least privilege

Comments 1
1 min read

Want to connect with Auth By Example?

Create an account to connect with Auth By Example. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
A share link is a scoped grant, not permanent access

A share link is a scoped grant, not permanent access

Comments
1 min read
Search results still need authorization filters

Search results still need authorization filters

Comments
1 min read
A list endpoint must filter by authorization

A list endpoint must filter by authorization

Comments
1 min read
Email verified is not authorization

Email verified is not authorization

1
Comments
1 min read
Rate limiting is not authorization

Rate limiting is not authorization

Comments
1 min read
WebSocket subscribe is still authorization

WebSocket subscribe is still authorization

Comments 1
1 min read
MFA is not authorization

MFA is not authorization

Comments
1 min read
CORS is not authorization

CORS is not authorization

1
Comments
1 min read
Background jobs still need the caller's authorization

Background jobs still need the caller's authorization

Comments
1 min read
OAuth scopes are not object permissions

OAuth scopes are not object permissions

Comments
1 min read
Frontend visibility is not authorization

Frontend visibility is not authorization

Comments
1 min read
Service identity is not user permission

Service identity is not user permission

Comments
1 min read
A tenant claim is not tenant isolation

A tenant claim is not tenant isolation

Comments
1 min read
OAuth on MCP is not the same as authorizing each tool call

OAuth on MCP is not the same as authorizing each tool call

Comments
1 min read
Project access is not object permission

Project access is not object permission

Comments
1 min read
A stale authorization cache is not a current permission

A stale authorization cache is not a current permission

Comments
1 min read
Feature flags are not authorization

Feature flags are not authorization

Comments
1 min read
Tenant membership is not resource permission

Tenant membership is not resource permission

Comments
1 min read
Read permission is not export permission

Read permission is not export permission

Comments
1 min read
Page 2 of a list still needs the same authorization filter

Page 2 of a list still needs the same authorization filter

Comments 2
1 min read
mTLS proves which service called you — not what it may do

mTLS proves which service called you — not what it may do

Comments
1 min read
OAuth scopes are not your app's authorization model

OAuth scopes are not your app's authorization model

Comments 1
1 min read
Creating a child resource still needs a check on the parent

Creating a child resource still needs a check on the parent

Comments
1 min read
Frontend route guards are not authorization

Frontend route guards are not authorization

1
Comments
1 min read
Feature flags are not access control

Feature flags are not access control

1
Comments
1 min read
An internal network is not a permission

An internal network is not a permission

Comments
1 min read
Batch APIs still need per-item authorization

Batch APIs still need per-item authorization

Comments
1 min read
Validate the JWT audience claim

Validate the JWT audience claim

Comments
1 min read
Pull the tenant from the auth context, not the request body

Pull the tenant from the auth context, not the request body

Comments 1
1 min read
Authorize the object, not just the route

Authorize the object, not just the route

Comments 1
1 min read
Separate who can grant from who can act

Separate who can grant from who can act

Comments
1 min read
Never trust a client-supplied tenant ID

Never trust a client-supplied tenant ID

Comments
1 min read
Check permissions again after every trust boundary

Check permissions again after every trust boundary

Comments
1 min read
Default-deny beats allow-everything-then-trim

Default-deny beats allow-everything-then-trim

Comments
1 min read
loading...