Isolation applies beyond ordinary routes
You have learned to constrain task queries by workspace. The next question is where tenant data travels after that query.
An HTTP route is only one path. Taskboard also stores idempotent results, delivers background jobs, broadcasts real-time changes, and records logs. Each path can cross a tenant boundary if it loses context.
Cached results can become an access pathโ
An idempotency record lets a client retry an operation and receive its saved result. That record must be scoped to the actor, workspace, operation, and key.
The server must also authorize the caller before replaying a saved response. Maya might create a task and later lose Acme membership. Possession of the old idempotency key must not restore access to Acme's data.
A future read cache needs similarly complete keys. A key containing only tasks cannot distinguish Acme's task list from Orbit's. Even a workspace-aware key needs a policy for role-dependent data and stale permissions.
Taskboard does not require a general read cache to teach this risk. The same reasoning applies to any stored response introduced later.
Background work must carry ownershipโ
A job needs the workspace and identifiers relevant to its operation. Looking up a task by ID and forgetting its tenant turns a delayed path into an unscoped query.
Stored jobs also contain trusted-at-creation context that may become stale. A membership can change before delivery. Decide whether an operation represents a committed business fact or requires fresh authorization at execution.
Connected clients remain subject to permissionsโ
A Socket.IO room is a delivery group, not an authorization proof. The server must authorize joining, and later delivery must account for revoked membership. Guessing a room name must not let an Orbit user subscribe to Acme events.
Logs and metrics also need boundaries. A request identifier is useful for correlation. Logging full tokens, invitation links, or sensitive task bodies can expose data to people who only need operational access.
Production isolation tests should attempt cross-tenant reads, writes, relationship creation, replay, and real-time subscription. A happy-path test that checks only Acme's own response cannot detect an Orbit leak.
Why authorize before returning an idempotent response?
The saved result may contain tenant data, and the caller's membership may have changed since the original operation. Replay is still an access decision.
Tenant scope must survive every path that stores, processes, or delivers tenant data. Look beyond the route that first accepted the request.
Read api/src/tenancy.ts Read api/src/jobs.ts Read api/src/realtime.ts