CodeZettaInterview Hub

NestJS · Authorization · Mid-Level · Scenario

How do you authorize user can edit own post?

Short Interview Answer

Load resource, compare ownerId to user.id (or policy check), throw Forbidden if mismatch.

Detailed Explanation

Don't trust client-provided ownerId. Prefer ID from route plus server lookup. Guards can pre-check with Param.

Did you know this answer?