The rule
Every query and mutation that returns or modifies data must verify the caller has access.Patterns
Per-user
Per-workspace
Per-role
Common mistakes
Filtering only on the client
Filtering only on the client
“I only show the user their own tasks in the UI” — but the API endpoint returns everything. Anyone who sniffs the network can see all tasks.
Trusting URL params
Trusting URL params
/tasks/123 — server should verify the user has access to task 123, not just trust the URL.Forgetting the membership check on workspace queries
Forgetting the membership check on workspace queries
Filtering by
workspaceId is necessary but not sufficient. Verify the user is a member of that workspace too.Tips
Related
Roles & permissions
Role model.
Multi-tenancy
Per-tenant patterns.
Auth integration
The
ctx.auth API.