Browse / Security Testing / User-Scoped Data Filtering

User-Scoped Data Filtering

Implements secure multi-tenant data access patterns and ownership verification using Python, FastAPI, and SQLAlchemy.

SkillSecurity TestingIntegrations

The source repository doesn't declare a license. Check its terms before reusing the code.

Key features

  • Standardized user context extraction from authentication tokens
  • Safe administrative bypass and data access audit logging
  • SQLAlchemy patterns for automatic scoped database filtering
  • Multi-tenant architecture support for organization-level scoping
  • Ownership verification via decorators for secure write operations

Use cases

  • Implementing secure administrative tools with full data access and audit trails
  • Restricting users to only see and manage their own data in a SaaS application
  • Building a multi-tenant platform where data must be isolated by organization

FAQ

Does this skill support organization-level multi-tenancy?

Yes. It includes patterns for both individual user-level scoping and higher-level organization or team-based data isolation, making it ideal for B2B applications.

When should I use this skill with Claude Code?

Use this skill whenever you are building multi-user or SaaS applications where users should only see their own data. It is specifically optimized for developers using Python, FastAPI, and SQLAlchemy.

What does the User-Scoped Data Filtering skill do?

This skill provides Claude with specialized patterns for implementing secure data access layers. It helps automate the process of extracting user context from tokens, applying automatic database filters in SQLAlchemy, and verifying resource ownership.

How does this skill improve my development workflow?

It reduces manual coding for security checks by providing reusable decorators and dependency injection patterns. This ensures consistent security across your entire API and minimizes the risk of accidental data leaks.

How does this skill handle administrative data access?

The skill provides a safe administrative bypass pattern. This allows authorized admins to view all data while ensuring that every access event is recorded in a secure audit trail for compliance.