vulns.co
/
GKData.io MCP
ID / Identity

Access control and tenant boundaries

Review whether every protected operation binds the caller, tenant, resource, and action together at the decision point.

Guide 02 / 154 review notesUpdated 2026-10-11

The review

What to look for

Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.

  1. Write the invariant

    State who may perform which action on which resource in which tenant; include inherited and combined views.

  2. Trace enforcement

    Follow each server-side route, resolver, or service call to the authorization decision and note alternate interfaces.

  3. Check stale authority

    Review exports, pagination, saved views, and cached references for a fresh permission decision before disclosure.

  4. Preserve evidence

    Compare permitted and denied outcomes using only owned objects and record the expected policy result.

What to produce

  • Authorization invariant table
  • Enforcement trace
  • Documented allow and deny evidence

Common mistakes

  • Relying on UI visibility as authorization
  • Checking only one API path
  • Forgetting tenant context on background work

Continue the study

Reading & source context

Editorial notes above connect these references. Open each record for its original source and review date.

Visual models

Connected disclosures

From the field toolkit

Guide by GK Data · Research snapshot 2026-10-04.
Sources and review dates are preserved in the library provenance.

Next skillSession, cookies, and passkeys →