DEV Community

Auth By Example
Auth By Example

Posted on

Your notification bell can show titles the user can't open

When someone comments on a doc, a lot of apps insert a row into notifications and later load those rows for whoever is signed in. The feed query usually filters by recipient_user_id and stops there.

If that person lost access to the doc (removed from the project, folder moved, share revoked), the bell still shows the title and a snippet. The detail page correctly 404s. The bell already gave away that the doc exists and what people said about it.

Keep the resource id on the notification. Before you return each row, run the same read check you use on the show endpoint. Drop rows that fail, or swap the title for something generic like "You no longer have access to this item" without the original name. Expire cached bell payloads the same day access changes.

Quick test: notify a user about a comment on doc A, revoke their read on A, reload the bell, and confirm doc A's title is gone.

Top comments (1)

Collapse
 
dev_in_the_fog profile image
Jason Y. (dev_in_the_fog) •

Really thoughtful post! Documenting real-world engineering hurdles and actionable solutions like this brings immense value to the community.