← Inspection rules
SEC-014 / v1.0.0 / 2026-10-02
Inspect query authorization and retrieval limits
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Environments where user or organization identity determines accessible data, including bulk-query controls.
Where to look first
- API routes, authorization, tenant filtering, and database queries
- Pagination, exports, retrieval limits, and monitoring configuration
Inspection steps
- Inspect server-side caller and record authorization; use evidence from an authorized test environment for unauthenticated, insufficient-role, and cross-tenant denial.
- Inspect per-user and per-tenant volume limits and detection, including repeated ordinary requests, pagination, and access spread across endpoints.
Remediation direction
- Centralize server-side authorization and set appropriate limits and alerts; verify allowed and denied queries with synthetic data.
Evidence required for completion
- Record API coverage, role/ownership combinations, allow/deny results, retrieval limits, and alert evidence; identify untested endpoints and exports.
Limits and unverified scope
- Limits do not repair authorization flaws. Do not exercise bulk requests or real customer queries in production; unavailable permissions or test evidence mean unverified.