← Inspection rules

SEC-014 / v1.0.0 / 2026-10-02

Inspect query authorization and retrieval limits

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Environments where user or organization identity determines accessible data, including bulk-query controls.

Where to look first

  • API routes, authorization, tenant filtering, and database queries
  • Pagination, exports, retrieval limits, and monitoring configuration

Inspection steps

  1. Inspect server-side caller and record authorization; use evidence from an authorized test environment for unauthenticated, insufficient-role, and cross-tenant denial.
  2. Inspect per-user and per-tenant volume limits and detection, including repeated ordinary requests, pagination, and access spread across endpoints.

Remediation direction

  • Centralize server-side authorization and set appropriate limits and alerts; verify allowed and denied queries with synthetic data.

Evidence required for completion

  • Record API coverage, role/ownership combinations, allow/deny results, retrieval limits, and alert evidence; identify untested endpoints and exports.

Limits and unverified scope

  • Limits do not repair authorization flaws. Do not exercise bulk requests or real customer queries in production; unavailable permissions or test evidence mean unverified.

Additional references