Goal
Make sure agents distinguish authentication from authorization when implementing protected resources.
Repository Context
This API uses session-based authentication and organization-scoped authorization.
workspace-api/
├── src/
│ ├── auth/
│ ├── routes/
│ ├── services/
│ └── repositories/
├── tests/
├── package.json
└── AGENTS.md
Authentication determines who the current user is.
Authorization determines whether that user may access a specific organization or resource.
A valid session alone does not grant access to every authenticated resource.
Current AGENTS.md
# Project Instructions
## Authentication
- Require a valid session for protected routes.
- Once a user is authenticated, allow access to protected resources.
## Development
- Keep authentication logic in `src/auth`.
## Validation
- Run authentication tests after changing protected routes.
Your Task
Fix the security instructions so authentication alone does not grant resource access.
Require authorization checks for the relevant organization or resource in addition to a valid authenticated session.