DEV Community

Auth By Example
Auth By Example

Posted on

Print preview can still show records the user lost access to

A lot of apps build print or PDF preview by loading the same record the detail page uses, then rendering a printer-friendly layout. The preview route often got added later, so it only checks that someone is signed in.

If that person lost access (role removed, share revoked, moved out of the folder), the normal detail page returns 404. The print URL still loads the title, fields, and maybe related rows. Anyone with an old tab or a bookmarked /print link keeps seeing it.

Reuse the same read check the show endpoint uses before you assemble the preview. If the check fails, return 404 with no body rather than a stripped template that still names the record. Drop any cached preview HTML the same day access changes.

Quick test: open print preview on record A as a viewer, revoke their read on A, reload the preview URL, and confirm you get a 404 with no title in the response.

Top comments (0)