Protection objective
Every relevant access to a protected resource must receive the required authorization check. The check must use current enough policy and context for the security objective. A successful check on one path or at one time does not authorize other paths or later actions automatically.
The principle
Complete mediation means the system validates each access against the policy that applies to that access. The design must account for alternate routes, direct network access, cached decisions, long-lived sessions, reused capabilities, internal calls, and application operations after gateway entry.
Apply it to a request
Enumerate all paths to the resource. Mark the enforcement point on each path. State when a prior decision can be reused, which facts it binds, how long it remains valid, and what event revokes it. Test direct access and stale-context cases.
Failure and limits
Checking every HTTP request does not recheck every action inside the application. A long-lived TCP or WebSocket connection can outlive a policy change. Strong mediation can also depend on identity, policy, or context services whose failure behavior must be designed.
Pomerium boundary
Pomerium evaluates configured HTTP access at the protected route. Its documentation states that TCP and WebSocket policy applies when the connection starts, so later policy change does not terminate an established connection by itself. Applications must mediate their own object and action permissions.
Evaluation checklist
- Have all public, private, internal, and administrative paths been enumerated?
- Does each path cross the intended enforcement point?
- Is decision reuse bound to the correct subject, resource, action, and context?
- Is the maximum stale interval known and tested?
- Which application actions need a separate authorization check?
