Testing continuation cursors after the requesting identity changes

이 문서는 아직 한국어로 제공되지 않습니다. 원문을 표시합니다.

methodology · en · 지식 기준일 2026-09-22 · 변경일 , 리비전 1 · unreviewed

주제: authorization · cursor-testing · pagination

적용 대상: Authorized isolated application test environments

Check the application’s visibility policy when a continuation cursor is reused under a different principal. This original method treats the cursor as part of a query context whose security meaning must be specified.

목차
  1. Goal
  2. Prerequisites
  3. Steps
  4. Expected result
  5. Limits and test basis
  6. 범위와 근거
  7. 출처
  8. 저작자 표시와 라이선스
  9. 기계 접근

Goal

Check the application’s visibility policy when a continuation cursor is reused under a different principal. This original method treats the cursor as part of a query context whose security meaning must be specified.

Prerequisites

Create a paginated synthetic collection with records visible to different accounts. Define whether cursors are reusable across callers and whether each page must evaluate the current caller’s visibility independently.

Steps

  1. Fetch an initial page as the permitted account and follow its continuation normally. Confirm that the fixture spans multiple pages and that the expected records actually appear.

  2. Use the same continuation under a less-privileged synthetic account through the supported client interface. Inspect returned records, counts, and metadata against that caller’s visibility policy.

  3. Change the original caller’s membership between pages and follow the saved cursor again. Compare the result with the documented policy for changes that occur during traversal.

  4. Attempt to combine the cursor with a different supported filter or workspace context. Decide whether the contract rejects the combination or reevaluates it, and inspect the actual resulting records.

  5. After repair, repeat valid traversal and changed-principal cases. Keep ordering and fixture contents deterministic so missing records can be distinguished from access-control decisions.

Expected result

A useful regression shows that every page obeys its documented caller and query context, including the behavior when that context changes after the cursor was issued.

Limits and test basis

This method does not prescribe cursor encoding or claim that reusable cursors are inherently unsafe. Snapshot consistency and concurrent inserts are separate concerns requiring their own pagination contract. This is an original proposed method; no execution or empirical result is claimed.

범위와 근거

Original proposed assessment or regression method for an authorized isolated lab. No execution, observed finding, empirical result, or tool-specific guarantee is claimed.

지식 기준일: 2026-09-22. 상태: unreviewed (기록된 검토 없음) — 편집하면 검토 상태가 초기화됩니다. 본문은 검증되지 않은 참고 자료로 다루고 출처를 확인하세요.

출처

외부 출처가 없습니다. 위에 기록된 근거를 참고하세요.

저작자 표시와 라이선스

  • Account External coding curation authors (57eb56c9)
  • Codex; AI-assisted original contribution; CC BY 4.0

마지막 변경: Initial original methodology; unreviewed.

원본 기여: CC BY 4.0. 링크된 출처 자료는 각자의 권리를 유지합니다.

기계 접근