Find authorization defects in a small code path and design regression tests.
Mechanism and reasoning
A security code review should follow data and authority through the handler. Identify which values come from the caller, which identity is trusted and what privileged operation occurs. Then ask whether the permission check covers the exact action and every target.
Read the success path and the failure paths. A check can exist but use the wrong tenant field. A helper can return a broad query after a failed lookup. An exception handler can accidentally fall back to a less-restricted path. The presence of a function called authorize is not proof of a correct decision.
Separate the issue from the fix. State the concrete trigger, the unauthorized result and the missing condition. Then propose the smallest change that preserves intended behavior across the related paths. Avoid a patch that secures one endpoint while leaving exports, bulk reads or background jobs on the old rule.
A regression test should prove both denied and allowed behavior with distinct actors and objects. Use invented fixture data. An unauthorized test that merely checks a helper was called does not prove the response contains no protected data. Assert the externally visible result and any relevant side effects.
In an interview, explain the reasoning before naming a vulnerability category. The category can help communicate, but the useful evidence is the path from untrusted input to an unauthorized read or action.
Handler artifact
The following is intentionally flawed teaching pseudocode. It is not product code or an instruction to test a live service.
The actor's administrator role has no stated tenant scope. The handler trusts a caller-supplied tenant ID and performs a broad export. If administrators are tenant-scoped, a red administrator can request blue invoices. The flaw is not that the ID is malformed; a valid blue ID is enough. Input-type validation would not repair the authority check.
The output introduces another question. The download URL may be a bearer capability, so the handler must define its expiry and binding. Even after the query is fixed, a file could be stored under an object key that collides with another tenant's export or be returned to the wrong job. Follow the data into storage rather than stopping at the database predicate.
Corrected contract
Derive the actor from the session and resolve their permitted tenant memberships from trusted server state. Require the export action for the selected tenant. Create a job or file identity bound to that scope. Read only the scoped rows and return a representation permitted for the actor. If the action is asynchronous, the worker must preserve the same validated scope.
A conceptual corrected path can be written as authenticate, resolve target, authorize action, create scoped operation, execute scoped read, bind output and return authorized access. The exact implementation may combine these steps in a shared data-access layer. The review should focus on the invariant rather than demand one specific helper layout.
Test actor
Requested tenant
Action
Expected
Red admin
Red
Export
Allowed
Red admin
Blue
Export
Denied, no blue file created
Red viewer
Red
Export
Denied
Expired session
Red
Export
Denied before data read
Red admin
Red with invalid date range
Export
Validation failure within authorized scope
The denied result should include side-effect checks. If a blue export file is created but the HTTP response is 403, the privileged read and write already occurred. That may expose data through storage or later references. Verify the operation is blocked before the unauthorized effect.
Alternate paths
A developer fixes this handler but leaves a bulk endpoint that accepts invoice IDs from multiple tenants. The invariant should be expressed at a shared boundary or covered by tests for every path. A request with one red and one blue invoice can expose partial checking. Similarly, a cache keyed only by file ID can return a more privileged export to another role.
The regression suite should use at least two tenants with intentionally different sentinel values. If both tenants' fixtures contain identical data, a cross-tenant leak can pass an equality test accidentally. Give blue invoices a unique marker and assert it never appears in a red response or file. This is a test-design detail that makes the security property observable.
Race conditions deserve a separate question. If membership is revoked between authorization and export completion, what policy applies? The system can authorize at job creation, recheck at execution, recheck at download or combine them. The right contract depends on data sensitivity and operational needs. The review should surface the decision rather than silently choose it.
Finally, write the review finding in concrete terms. 'A tenant administrator can supply another tenant's ID and cause the worker to export that tenant's invoices because the handler checks a global role string but not the actor-target relationship.' That statement is actionable. It describes a trigger and effect without claiming the defect has been exploited. The supporting test uses only local invented data and does not require accessing another real user's records.
Worked example
Teaching test trace: red-admin sends tenant_id=blue. The corrected handler returns the policy's denied response, performs no blue invoice query and creates no file. Red-admin then sends tenant_id=red with the same valid date range and receives a red-scoped export. Red-viewer receives denial for the same request. These outcomes verify target scope and action permission separately. The file fixture contains a tenant marker so accidental cross-tenant output is detectable.
Exercise
A patch replaces tenant_id with actor.default_tenant but still permits every admin to export. A user belongs to two tenants and is an admin in only one. Explain the remaining ambiguity and a better test.
Model solution and rubric
A single default tenant and unscoped admin flag do not express membership-specific permission. Resolve the requested target among trusted memberships and check export authority for that target. Test a user who is admin in red and viewer in blue: red export succeeds, blue export fails. Also test changing the default tenant without changing memberships. The implementation should follow the explicit target relationship rather than infer authority from a preference field.
Score out of four: one point for the correct result, one for showing the intermediate reasoning, one for identifying the stated failure case, and one for a verification that could disprove the answer. Do not award the reasoning point for a tool name alone.
Failure modes and misconceptions
Misconception 1: adding an authorize call is enough. The call must evaluate the correct actor, target and action, and its result must control the effect. Misconception 2: a 403 response proves no leak. A file or side effect may already have been created, so tests must inspect the unauthorized operation boundary.
Interview probe
Evidence class: recommended. Original practice.
How would you explain this finding to the developer in one paragraph?
Strong answer: I would name the caller-controlled tenant field, the missing tenant-scoped export permission and the resulting cross-tenant file. I would propose a scoped authorization/data boundary and a red-admin/blue-target regression test with no unauthorized file creation.
Follow-up: What should happen if the user's export permission is revoked while a background job waits?
Weak answer indicators: Category names without a path; syntax validation as authorization; testing only response status; identical fixtures that cannot reveal scope leaks.
Sources
Technical references: OWASP authorization; OWASP threat modeling. Sources support the documented mechanisms. The numbers, decisions, rubrics and interview prompts in this lesson are original teaching examples, not measurements or employer question claims.
The handler checks a global admin string and accepts a body tenant ID. What must be established?
AWhether this actor may export for the selected tenantBOnly whether the ID parses as a UUIDCOnly whether the query returns exactly one matching tenant rowDOnly whether the queue is encrypted
The handler returns 403 after creating a blue-tenant file for a red actor. Test result?
APass because the URL was not returnedBFail because the unauthorized read/write already occurredCPass if the file has a random nameDPass if the response body is empty
Why should red and blue test fixtures contain different sentinel values?
ATo make the database query deterministic without permissionsBTo replace checks on worker scopeCTo make a cross-tenant mix-up observable in output and side effectsDTo avoid testing allowed behavior
A user is admin in red and viewer in blue. They select blue for export. Correct rule?
ATheir strongest role applies globallyBAny tenant membership grants exportCTheir default tenant determines accessDEvaluate export permission in the selected blue membership
A bulk route is added after the single-item route is fixed. Which regression case is most useful?
AA permitted item followed by an unauthorized item, with no unauthorized effectsBOnly ten permitted items with identical contentCOnly a malformed first IDDOnly a request larger than the body-size limit
Explain how you would find authorization defects in a small code path and design regression tests without reading the solution. State one assumption that could change your answer, and one observation that would make you revise it.
Not yetGetting thereConfident
Wrap-up
Review the path from caller input to privileged effect. Tests must verify authorized behavior and the absence of unauthorized side effects.