Full-text search can return hits your list page would hide
List endpoints filter by tenant and role before they return rows. Full-text search often hits Elasticsearch or Postgres tsvector with only a tenant_id term, then returns every matching document id. A contractor who can
List endpoints filter by tenant and role before they return rows. Full-text search often hits Elasticsearch or Postgres tsvector with only a tenant_id term, then returns every matching document id.
A contractor who can open two projects still gets titles and snippets from a third project they were removed from last month, because the search index was never filtered by their current grants. The projects list looks right. Search still surfaces the old project.
Run the same read check you use on the show endpoint for each hit before you add it to the response. Drop hits that fail, including snippet highlights. Re-index or post-filter so revoked access disappears from suggestions the same day.
Quick test: index three projects, revoke the user's access to one, search a unique word that only exists in the revoked project, and confirm zero hits come back.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.