Authorize before the expensive work starts
Authorization belongs at the front of the request, not after you have already done the hard part.
Common pattern: generate a big export, render a PDF, fan out to workers, or query a warehouse — then check whether the caller may see the result. That wastes compute, creates noisy logs, and can leak existence or timing signals even when you eventually return 403.
Better order:
- Authenticate the caller.
- Authorize the specific action on the specific resource (or collection).
- Only then start expensive work.
If authorization can change mid-job (long exports, async pipelines), re-check before you deliver or persist the artifact — a permission revoked after enqueue should not still produce a downloadable file.
Cheap checks first. Costly work second.
