Skip to content

Enforce ownership: no cross-account access #3

Description

@NomadicAlternative

Source: specs/001-taskflow-mvp/spec.md — FR-003, FR-009, SC-005

Security work, not a feature. It has to land with the first data-backed page, not after.

Acceptance criteria

  • Every read of a project or task is scoped to the signed-in user
  • Opening a record URL belonging to another account is refused, not silently empty
  • The rule lives in one place in the data layer, not repeated per page
  • Verified by hand: sign in as account A, copy a record URL from account B, confirm refusal

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1Priority 1 - criticalbackendBackend work

    Projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions