Auth & authorization
Who are you, and what may you touch?
How it fails
- Login works, but permissions are only enforced by hiding buttons in the UI
- Sequential IDs let any signed-in user read someone else’s records
- Tokens in localStorage, no expiry, rotation, or revocation story
What I put in place
- Server-side authorization on every route, tested with cross-tenant attempts
- Hardened sessions (httpOnly, rotation, revocation) or a managed IdP with SSO
- Roles and tenancy modeled in the data layer, not bolted on in the front end