noCV
ATOKEN-103 · Define token authority

Bind API token queries to the issuing organization

Practice briefBugAdvanced

An export identifier from another organization succeeds because the service checks token validity but omits tenant scope.

Focused work estimate
3h 30m + prerequisites
Priority in the scenario
Urgent
Engineering practice
Tenant isolation · Authorization

Estimated field mix

  • Security70%
  • Backend30%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional B2B export API uses long-lived tokens. Tokens copied between organizations can access too much, and revocation takes effect unpredictably.

Setup prerequisites

  • Create a local synthetic API and two isolated organizations.
  • Use generated disposable credentials only.

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Repository reads include the token organization.
  • Cross-organization IDs receive nondisclosing denial.
  • Authorization occurs before artifact-link creation.

Implementation constraints

  • Test repository boundaries as well as routes.

Verification to include

  • Read an export in the issuing organization.
  • Request a second organization's export and verify no signed-link provider call.

Deliverables

  • Tenant-bound repository guard

Rollout and recovery

Deploy the scope guard before further token distribution; inspect denied access metadata.

Value of the work

For the engineer: Practice authorization boundaries, credential lifecycle and safe diagnostics.

For the team: Review denial paths and operational control over service access.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.