ABAuth By Exampleinauthbyexample.hashnode.dev·6h ago · 1 min readA websocket push is still an authorization decisionSubscribing a client to a channel after login is not the same as authorizing every event you later push on that socket. The bug pattern User connects with a valid session. Server joins them to tenant00
ABAuth By Exampleinauthbyexample.hashnode.dev·8h ago · 3 min readSoft-delete does not revoke accessSoft-delete is a data lifecycle choice. Authorization is a security decision. Mixing them up is how tombstoned rows keep answering "yes" long after the product thinks they are gone. The bug pattern A 00
ABAuth By Exampleinauthbyexample.hashnode.dev·11h ago · 2 min readAuthorization needs fresh attributes, not yesterday's snapshotMost ABAC bugs I see are not bad rules. They are stale inputs. The policy says something like "finance can edit records tagged confidential, but only during business hours." That looks fine in a desig00
ABAuth By Exampleinauthbyexample.hashnode.dev·1d ago · 3 min readYour AI agent shouldn't be able to do everything you canA common way to wire up an AI agent is to hand it the user's session or OAuth token and let it call APIs "as the user." It's quick, and it feels safe, because the agent can't do anything the user coul00
ABAuth By Exampleinauthbyexample.hashnode.dev·1d ago · 1 min readImpersonation tokens still need target-user authorizationWhen support or admin tooling mints an impersonation / "act as" token, validating that the operator is allowed to impersonate is only half the check. Every subsequent read and write must still authori00