<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Data Security on Nalar</title>
    <link>https://nalar.dev/tags/data-security/</link>
    <description>Recent content in Data Security on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 07 Sep 2026 00:00:00 +0700</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/data-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Authorize Bulk Data Exports as Sensitive Actions</title>
      <link>https://nalar.dev/authorize-bulk-data-exports-as-sensitive-actions/</link>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0700</pubDate>
      <guid>https://nalar.dev/authorize-bulk-data-exports-as-sensitive-actions/</guid>
      <description>&lt;p&gt;An application may correctly authorize every page and API request yet still expose too much data through an export feature. The common mistake is treating &amp;ldquo;can read this data&amp;rdquo; and &amp;ldquo;can copy a large collection of this data&amp;rdquo; as the same security decision.&lt;/p&gt;&#xA;&lt;p&gt;They are not necessarily equivalent.&lt;/p&gt;&#xA;&lt;p&gt;A support agent who may view customer records one at a time might not need permission to download the entire customer directory. A project member who can inspect documents in a workspace might not be allowed to export documents from other workspaces. Even when every exported row is individually readable, collecting thousands of rows into one portable file changes the impact of a mistake or compromised account.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
