Skip to main content

Command Palette

Search for a command to run...

Authorize before the expensive work starts

Updated
•1 min read•View as Markdown
A
Practical lessons on auth, authorization, and access control.

Authorization belongs at the front of the request, not after you have already done the hard part.

Common pattern: generate a big export, render a PDF, fan out to workers, or query a warehouse — then check whether the caller may see the result. That wastes compute, creates noisy logs, and can leak existence or timing signals even when you eventually return 403.

Better order:

  1. Authenticate the caller.
  2. Authorize the specific action on the specific resource (or collection).
  3. Only then start expensive work.

If authorization can change mid-job (long exports, async pipelines), re-check before you deliver or persist the artifact — a permission revoked after enqueue should not still produce a downloadable file.

Cheap checks first. Costly work second.