Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Spring method authorization: reject a cross-tenant read

Last updated: 30 Sept 20264 min read
tutorial
IntermediateBy AITrove Editorial

A proxied service can compare the requested tenant with the authenticated principal before returning a tenant-scoped receipt.

Download Spring source kit

The downloadable Spring source kit checks this boundary with the named JUnit test and its pinned dependencies.

Check the resource scope at the service

The local test authenticates tenant-east, allows its receipt seven, and rejects the same method call for tenant-west. The rule uses the first method argument and Spring Security's authenticated name. It is applied to the managed bean, which means the call passes through method-security advice.

A broad receipt.read authority alone would not answer which tenant's receipt the caller may read. JWT validation establishes one trust input; this lesson adds a resource-specific decision after authentication. The identity and tenant mapping in this test are fixtures, not a production issuer or database policy.

Avoid bypasses and data leaks

Directly constructing the service skips its proxy. A public controller should not return a row before applying this check, including through list and export endpoints. A database query scoped by trusted tenant can reduce accidental cross-tenant reads, but must be tested against the target database and repository code.

Checked source

Java
static class TenantReceiptReader {
    @PreAuthorize("#p0 == authentication.name")
    public String read(String tenant, int receiptId) {
        return tenant + ":" + receiptId;
    }
}

Verification boundary

TenantReceiptAuthorizationTest.rejectsACrossTenantReadThroughTheManagedService runs in the Spring source kit. This excerpt omits imports and surrounding test setup; the downloadable kit contains the complete source.

Costs and boundaries

The test uses one local principal and one managed service method. It does not prove row-level filtering, real token-to-tenant mapping, identity-store correctness or authorization across every endpoint.

Common Mistakes

  • Do not confuse a valid token or broad scope with resource ownership.
  • Do not call a directly constructed object and expect proxy advice.
  • Do not accept a caller-controlled tenant header as authenticated identity.

Read next

Spring method authorization: test the proxied service boundary, Spring Security JWT resource server: validate trust before checking scope, Spring Security filter chain: authentication, CSRF and request order, Java interfaces and replaceable behavior.

Continue with Spring delivery contracts

Continue with Spring method security: reject a cross-tenant receipt mutation.

Continue with checked tenant security

Continue with Spring Security scope versus tenant ownership: two separate decisions, Spring JdbcTemplate tenant predicates: put ownership in the SQL query.

spring
spring-boot
tenant-receipt-authorization
Storage details