Spots

A batch API is not a free pass on every item

Batch and bulk endpoints are convenient: one request, many IDs. They are also a classic place where authorization shrinks to "caller can hit this route."

If your handler loads ten resources and returns

If your handler loads ten resources and returns whatever the IDs resolve to, a caller who is allowed to see one row can often learn about nine others. The same trap shows up on bulk update, delete, and "export these records" paths.

Authorize every item in the batch against the

Authorize every item in the batch against the current subject, tenant, and action. Fail closed on any ID the caller must not touch — do not silently skip it and keep returning the rest unless that behavior is an explicit, audited product choice. A route-level role check is necessary. Per-item authorization is what makes a batch API safe. For further actions, you may consider blocking this person and/or reporting abuse

News

A batch API is not a free pass on every item

Batch and bulk endpoints are convenient: one request, many IDs.

@spots #dev
Source: Dev.to
See more like this