A proxied service can compare the requested tenant with the authenticated principal before returning a tenant-scoped receipt.
Spring method authorization: reject a cross-tenant read
The downloadable Spring source kit checks this boundary with the named JUnit test and its pinned dependencies.
Check the resource scope at the service
The local test authenticates tenant-east, allows its receipt seven, and rejects the same method call for tenant-west. The rule uses the first method argument and Spring Security's authenticated name. It is applied to the managed bean, which means the call passes through method-security advice.
A broad receipt.read authority alone would not answer which tenant's receipt the caller may read. JWT validation establishes one trust input; this lesson adds a resource-specific decision after authentication. The identity and tenant mapping in this test are fixtures, not a production issuer or database policy.
Avoid bypasses and data leaks
Directly constructing the service skips its proxy. A public controller should not return a row before applying this check, including through list and export endpoints. A database query scoped by trusted tenant can reduce accidental cross-tenant reads, but must be tested against the target database and repository code.
Checked source
static class TenantReceiptReader {
@PreAuthorize("#p0 == authentication.name")
public String read(String tenant, int receiptId) {
return tenant + ":" + receiptId;
}
}Verification boundary
TenantReceiptAuthorizationTest.rejectsACrossTenantReadThroughTheManagedService runs in the Spring source kit. This excerpt omits imports and surrounding test setup; the downloadable kit contains the complete source.
Costs and boundaries
The test uses one local principal and one managed service method. It does not prove row-level filtering, real token-to-tenant mapping, identity-store correctness or authorization across every endpoint.
Common Mistakes
- Do not confuse a valid token or broad scope with resource ownership.
- Do not call a directly constructed object and expect proxy advice.
- Do not accept a caller-controlled tenant header as authenticated identity.
Read next
Spring method authorization: test the proxied service boundary, Spring Security JWT resource server: validate trust before checking scope, Spring Security filter chain: authentication, CSRF and request order, Java interfaces and replaceable behavior.
Continue with Spring delivery contracts
Continue with Spring method security: reject a cross-tenant receipt mutation.
Continue with checked tenant security
Continue with Spring Security scope versus tenant ownership: two separate decisions, Spring JdbcTemplate tenant predicates: put ownership in the SQL query.
