An export request can be authorized when it is submitted and become inappropriate before the resulting file is downloaded. A user may leave a team, lose a role, or have an account disabled while the export waits in a queue. The job runs later under a service identity rather than the user's browser session.

This creates several separate access decisions: who may request the export, which data the worker may include, and who may retrieve the completed artifact.

Preserve the original security context

OWASP's authorization guidance calls for validating permissions on each request and applying controls consistently across application paths. Background work needs an explicit policy for carrying or re-evaluating the relevant context. The authorization guidance provides the general principle.

An illustrative reporting service queues a customer export with the tenant, requesting user, selected dataset, and permitted filters. A worker must not infer the tenant from an unvalidated filename or trust arbitrary account identifiers supplied by the client. Its broad database access is implementation authority, not permission to export every record.

Decide how permission changes affect queued work

Some products require current authorization when a job starts and again when the result is retrieved. Other workflows intentionally preserve a formally approved snapshot request. The business must choose and document the intended semantics rather than letting queue timing make the decision.

If an approved export survives a role change, define who may receive it and why. If revocation cancels it, define how cancellation reaches queued and running workers. These choices affect audit evidence and the user experience as well as access control.

Test the intervals between stages

Create a synthetic export, pause the worker using a supported test mechanism, and remove the user's access. Resume processing and check the result against the documented policy. Repeat with revocation after generation but before download.

Use two test tenants to inspect job status endpoints, object storage paths, email notifications, and download links. A protected export file can still disclose its existence or metadata through an unprotected status endpoint. Record which information each role is allowed to see.

Include retries and cleanup

A retried job can create several artifacts if generation is not tied to a stable job identity. Verify which file is considered current and how abandoned outputs are removed. Ensure that an expired download link does not leave another public path to the same data.

The assessment can produce a state-transition record covering submission, execution, completion, delivery, and deletion. For a business processing customer records, that record explains when authorization is evaluated and how long exported copies remain available. It also provides focused regression cases when changing queue systems, storage providers, or export formats.

Sources

OWASP: Multi-Tenant Security. The reporting service and worker pause are illustrative.

Back to the blogExplore Ceron