# Fintech authorization test harness

This synthetic example checks one account access rule with Bun. It has no network calls or customer data.

## Download and run

Install Bun from https://bun.sh/docs/installation. Save these three files in one folder:

- [auth.ts](./auth.ts): account access rule.
- [auth.test.ts](./auth.test.ts): allowed, denied, and malformed-input cases.
- [LICENSE](./LICENSE): MIT license. Keep its notice when reusing the code.

From that folder, run:

```sh
bun test auth.test.ts
```

No package install is needed. The current suite has nine tests.

## The rule

A customer may view an account only when the owner ID and tenant ID match. An approver from the account's tenant may pass the narrow `release` rule. Other roles, unknown actions, missing records, and blank IDs return `false`.

Get actor fields from a verified server session and account fields from trusted storage. Never let the request body choose its own role, tenant, or owner. Input validation cannot prove those fields are true.

`release` here checks only a role and tenant. It does not approve or send a real payment. A full payment rule also needs the exact amount and destination, limits, account state, a distinct maker and approver, and a current approval record.

## Connect a real route

Keep the unit tests and add a separate local API adapter. Seed two tenants and two owners. Send each actor/resource/action pair with that actor's test session. Check response status, private data in the response, and database side effects. A 403 response after a ledger write is a failed test.

The suite proves the demo rule works. It does not test authentication, storage, route handling, or concurrent payment approval. Use test data and a local test app when adding those checks.

Sources:

- https://api-security.owasp.org/editions/2023/en/0xa1-broken-object-level-authorization/
- https://cheatsheetseries.owasp.org/cheatsheets/Authorization_Cheat_Sheet.html
