Your notification bell can show titles the user can't open
When someone comments on a doc, a lot of apps insert a row into notifications and later load those rows for whoever is signed in. The feed query usually filters by recipient_user_id and stops there. If that person lost
When someone comments on a doc, a lot of apps insert a row into notifications and later load those rows for whoever is signed in. The feed query usually filters by recipient_user_id and stops there.
If that person lost access to the doc (removed from the project, folder moved, share revoked), the bell still shows the title and a snippet. The detail page correctly 404s. The bell already gave away that the doc exists and what people said about it.
Keep the resource id on the notification. Before you return each row, run the same read check you use on the show endpoint. Drop rows that fail, or swap the title for something generic like "You no longer have access to this item" without the original name. Expire cached bell payloads the same day access changes.
Quick test: notify a user about a comment on doc A, revoke their read on A, reload the bell, and confirm doc A's title is gone.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.