Original Summary

Wanted to verify that removing someone from a team actually revoked their access in real time, not just in theory. Turns out I couldn't even run that test, because there was no way for a user in two orgs to switch between them in the UI. Building the switcher was the easy part. While wiring it up I went through everywhere the app decided which organization a request belonged to. Six places, not the two I expected. Two of them were the billing checkout and billing portal routes, and both of them just trusted an organizationId sent from the client instead of checking it against the session. Nothing had exploited that as far as I know, it just would have let a logged-in user point a billing action at an organization they weren't a member of. Fixed all six the same way and added a script that fails the build if anyone, including future me, reintroduces the old pattern. Ran it against a deliberately broken test file first to make sure it actually catches the thing it's supposed to catch, not just passes by accident. Still haven't finished the original test. That's next.   submitted by   /u/NatureAccording1655 [link]   [comments]


  • 情报分类:综合情报
  • 分类依据:内容未命中明确的垂直分类规则,归入综合情报
  • 信息来源:Reddit · SideProject
  • 发布时间:2026/9/29 22:18:40