DEV Community

Auth By Example
Auth By Example

Posted on

Archiving a workspace should make the API read-only too

Archiving usually ships as a UI change. The workspace moves to an "Archived" tab, the edit buttons go grey, and everyone moves on.

The API often never hears about it. A script with an old token, a webhook handler, or a teammate with a bookmarked form can still create tasks, rename files, or invite people into a workspace that's supposed to be frozen. Billing tends to break the same way: a customer downgrades or stops paying, the screens lock, and writes keep landing.

What helps:

  • Put the workspace state into the permission check itself. "Can this user edit tasks here?" should come back no when the workspace is archived, whatever role they hold.
  • Keep reads working. People archive things so they can still look them up later.
  • Decide what unarchiving needs. Usually that's an admin or owner action, and it should be checked and logged like any other role change.
  • Cover background jobs. Imports, syncs, and scheduled automations that write into the workspace should check the same state before they run.

Quick test: archive a workspace, then send a create or update request straight to the API with a token that was valid before. You want a 403 with a clear reason. A 200 means the archive only exists in the UI.

Top comments (0)