Security, Governance and Platform · Principal
User A was allowed to read a case. Why did the cached decision let user B in?
Take a few minutes to form your approach. Then open a worked answer and compare the decisions.
Reveal a worked answer
Start with the actual cache key, not the policy expression. An authorization answer is about a principal taking an action on a resource under some context. If a gateway caches allow by route or tenant alone, a later request can reuse that decision for another principal or another case. A correct policy service cannot fix a missing input in the cached lookup. Amazon Verified Permissions represents an authorization request with principal, action, resource and context. API Gateway's Lambda authorizer documentation explains how configured identity sources form the cache key, and warns that simple responses apply to matching cached identity-source values.
Draw two calls through the same route. A reads case 91 and gets an allow. B then asks for case 91, or A asks for private case 92. Which exact key does the gateway look up? If it does not distinguish the policy inputs that change the outcome, caching is unsafe. Include subject identity, tenant, action and resource scope as required by the policy. If the decision depends on record owner, purpose, policy version or time, either include those in a bounded key and invalidate on change, or avoid caching that decision. Do not put raw bearer tokens or sensitive attributes in observability labels just to make the cache convenient.
I would replay the A-allow/B-deny pair with caching enabled and disabled, then change a case's owner and repeat. Compare cache hit logs with the policy service's would-have-decided result in a controlled test. For immediate containment, disable the faulty cache or its affected route, invalidate existing entries and check access logs for cross-user reads. A short TTL reduces the exposure window but does not make a wrong cache key correct.
One subtlety is that some gateways cache a scoped policy rather than a bare boolean. Inspect what is cached and what the gateway enforces on a hit. If the cached policy is narrow enough for the requested resource and action, it may be safe with a coarser lookup than a simple allow flag. A semantic cache served tenant A's private answer to tenant B. What now? addresses a semantic answer cache returning another tenant's text. This is an earlier decision boundary where authorization itself was incorrectly reused.
Continue reading
Related questions
Read beyond the question
Explore more security, governance and platform
Follow another question in this area, or search the complete Question Library.
Browse this area →Browse Question Library →