All challengesCHALLENGE 15 OF 25

Fix Authentication vs Authorization

Keep identity checks distinct from access control.

Intermediate

Goal

Make sure agents distinguish authentication from authorization when implementing protected resources.

Repository Context

This API uses session-based authentication and organization-scoped authorization.

Code exampleMarkdown
workspace-api/
├── src/
│   ├── auth/
│   ├── routes/
│   ├── services/
│   └── repositories/
├── tests/
├── package.json
└── AGENTS.md

Authentication determines who the current user is.

Authorization determines whether that user may access a specific organization or resource.

A valid session alone does not grant access to every authenticated resource.

Current AGENTS.md

Code exampleMarkdown
# Project Instructions

## Authentication

- Require a valid session for protected routes.
- Once a user is authenticated, allow access to protected resources.

## Development

- Keep authentication logic in `src/auth`.

## Validation

- Run authentication tests after changing protected routes.

Your Task

Fix the security instructions so authentication alone does not grant resource access.

Require authorization checks for the relevant organization or resource in addition to a valid authenticated session.

YOUR AGENTS.mdEdit the Current AGENTS.md shown in the challenge
AGENTS.mdMarkdown
Loading editor…

Sign in to save progress across devices.

Your answer is checked locally against the challenge rules. No AI is used for evaluation.