Worked role example
Claim A has a medical PDF and a generated preview. Reviewer R is assigned to A, while reviewer S is assigned to claim B. R may open A under the role rule; S must be denied for A, including a direct preview URL. After R is removed from A, an old download link must stop granting new access where the storage design supports revocation. If a short-lived link cannot be revoked, document that window and restrict link lifetime. Use fake documents in this test. Do not place real medical files in a public test bucket.
Test access as a matrix
Create one claimant, another claimant, an assigned reviewer, an unassigned reviewer, and a former employee. Test list, preview, download, upload, and delete for each role. Repeat after a reviewer is reassigned.
Checks to run
- Check claimant, assigned reviewer, supervisor, and inactive staff roles against each document action.
- Expire signed download links and recheck permission when a new link is issued.
- Test reassignment, closed claims, bulk export, and revoked staff access.
Document lifecycle
Check new upload, virus scan result, preview image, download, archive, and deletion. A thumbnail can leak the same information as the full PDF. Test whether the search index and export job apply the claim permission rule too.
When a reviewer leaves the team, deny new authenticated downloads and exports; record the remaining lifetime of issued bearer links. Keep only the access metadata needed for audit; do not store document contents in ordinary request logs.
One more boundary test
Add a shared-device test. A claimant downloads a document, signs out, and another claimant signs in on the same browser. The second person must not see the first person’s preview from a client cache or a service worker. Test the browser back button and an old tab after logout. For exports, make the job recheck the requester’s role before it hands over the finished archive. A permission check only when the job starts can be stale by the time the file is ready.
Test a copied document link
Create claim C-01 for customer A and upload one medical file. Give customer B the document ID and the full URL. Authenticated direct-download and thumbnail routes must deny access; test issued bearer links under their separate lifetime rule. Then remove A from C-01 and retry an old signed URL. The URL must expire within its stated lifetime, and a new URL request must check the current claim role. For a staff reviewer, permit only the claim assigned to that reviewer and log the read. OWASP says each endpoint using an object ID needs an object-level authorization check. Check file, preview, and metadata endpoints separately.
Pick an authenticated or bearer-link model
An authenticated download endpoint must deny customer B even if B knows the document URL. A presigned storage URL is a bearer credential: anyone holding it can use it while valid, subject to the storage policy. For strict current-role checks, deliver through an authenticated endpoint or a gateway that checks permission on every fetch. If presigned links are used, issue them only after authorization, use a short lifetime, and record the remaining exposure after role removal. Test an old link before and after expiry and a new-link request after revocation. Do not claim that forwarding a valid bearer link always produces a denial.
Amazon S3 explains presigned URLs as bearer tokens. Apply that limit when this storage design is used.
Primary sources
Next step
Revoke a claims reviewer in a test account and check old document links, previews, search, and exports. Read the related guide. For a review of your own system, request a security review.