Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Private Export Authorization and Artifact Scope

Last updated: 4 Oct 20266 min read
tutorial
IntermediateBy AITrove Editorial

A private export is a delayed read over many records. Authorization at the button click is only the first boundary. The server must authorize the requested scope before enqueueing, and the worker must load only permitted records when producing the artifact. The final download requires a separate access check or a short-lived grant bound to a specific artifact and recipient. A status endpoint must not reveal another user’s export name, row count, or progress. Artifact IDs should be opaque but opacity does not replace checks. Temporary objects, CDN caches, and range requests need the same privacy rules as the original data.

Working case

Reviewer 29 requests an export of 62 cases in organization 6. Before the worker starts, the reviewer loses membership. The product’s chosen rule is to cancel pending generation and mark the request Denied without exposing counts. A different approved policy could retain a narrow immutable grant, but it must be explicit and time-limited. The artifact, if produced, carries tenant, requester, filter, creation time, and expiration metadata. Reviewer 62 from organization 9 cannot obtain it by guessing its ID or changing a status URL. A public cache cannot store its response.

Implementation boundary

javascript
function mayDownload(actor, artifact, now) {
  return actor.userId === artifact.requesterId && actor.tenantId === artifact.tenantId && now < artifact.expiresAt;
}
console.log(mayDownload({ userId: 29, tenantId: 6 }, { requesterId: 29, tenantId: 9, expiresAt: 80 }, 47));
// Output: false

The predicate illustrates scope; the server must verify current policy or a narrowly minted grant before returning bytes. Store the exact normalized filter and tenant with the job, then bind the worker query to them. Exports should avoid embedding a broad service credential in a user-visible URL. A signed URL, when used, needs a short expiry and artifact-specific scope, with a plan for revocation and logging. Set private response caching headers, control CDN behavior, and validate range resume against the same immutable artifact. Delete expired artifacts and job metadata under a retention schedule. Treat unauthorized status and download requests consistently without revealing artifact existence unnecessarily.

Cost and boundaries

Export generation is at least O(n) in the number of included records and may require O(b) temporary storage for b output bytes. Rechecking policy adds limited work compared with scanning or serializing a large dataset. Short artifact TTLs reduce exposure and storage but can frustrate slow downloads; range support requires immutable bytes and validator handling. Encrypting and storing each artifact has operational cost, especially if multiple tenants request similar filters. Measure artifact count, unauthorized attempts, expiry cleanup lag, and bytes served from a private cache path.

Failure trace

The job endpoint checks tenant scope, but the worker runs a query using only the date range and exports cases from all organizations. A later status page exposes the total count to anyone with the job ID. Scope the worker query and status route independently. Another failure sends the artifact through a public CDN with a URL that lives for a week. Guessing the URL is not the only risk; links can appear in logs, browser history, or referrers. Keep grants narrow and short-lived, and test cache behavior with two accounts.

Verification

  • A forged filter or tenant cannot widen the worker result set.
  • Another account cannot infer private status or retrieve an artifact by ID.
  • Expired or revoked artifacts have a verified cleanup path.

Practice drill

Request an organization-6 export, then forge organization 9 in the job payload. Inspect worker query parameters and generated rows. Change membership between request and worker start, and verify the chosen revocation policy. Have another user request status and download using the artifact ID; neither may reveal content or metadata. Test artifact expiry, private cache headers, range resume across revisions, and deletion of temporary files after failure. Verify a failed worker leaves no partially downloadable artifact labeled complete.

Decision note

Authorize export request, worker query, status, and download as separate private boundaries.

Common Mistakes

  • Authorizing only the initial export button.
  • Assuming an opaque artifact ID is enough protection.
  • Putting a private artifact behind public caching.

Connected lessons

Authorization and Tenant Boundaries; Object-Level Authorization for Reads and Writes; Tenant Scope in Cache and Background Work; Permission Revocation and Active Sessions; Large Export Download and Integrity; Search Permissions and Private Results; Accepted Operations and Status Resources.

Apply and check

Build Project: tenant-safe case export and review Web Development: authorization and data lifecycle decisions quiz.

web-tech
web-development
Storage details