NestJS · Authorization · Mid-Level · Scenario
How do you authorize user can edit own post?
Short Interview Answer
Load resource, compare ownerId to user.id (or policy check), throw Forbidden if mismatch.
Detailed Explanation
Don't trust client-provided ownerId. Prefer ID from route plus server lookup. Guards can pre-check with Param.