Make repeated cancellation safe and tenant scoped
A client double-clicks Cancel while a support agent cancels from another screen. The connector must converge on one cancellation without allowing another tenant to cancel by event ID.
- Focused work estimate
- 1h 45m + prerequisites
- Priority in the scenario
- High
- Engineering practice
- Authorization · Idempotency · Lifecycle design
Estimated field mix
- Integrations50%
- Security30%
- Backend20%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional consultancy books appointments across time zones. The first connector duplicates events after timeouts and offers slots during stale calendar sync. Use a local calendar-provider double and synthetic calendars.
Setup prerequisites
- Create a local provider double for free/busy, event creation, updates, cancellation, and expiring tokens.
- Use synthetic calendars and an injected clock; no calendar account or outgoing invitation is required.
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
- CAL-101 · Reject local times that do not identify one instant
- CAL-102 · Merge overlapping busy intervals before offering slots
- CAL-103 · Label unavailable or stale free/busy data instead of showing open slots
- CAL-104 · Reserve a slot atomically when two customers choose it
- CAL-105 · Reconcile a create-event timeout before trying again
Acceptance criteria
- Cancellation resolves the booking through tenant and actor authorization before accessing provider IDs.
- Repeated authorized cancellation converges on the same terminal result.
- Provider not-found is accepted only after verifying the expected booking/provider mapping, and other provider errors remain visible.
Implementation constraints
- Keep provider event IDs out of caller-controlled authority decisions.
Verification to include
- Send concurrent cancellation requests and assert one logical cancellation history.
- Attempt cancellation from another tenant and verify no provider request is made.
Deliverables
- Scoped cancellation service and idempotency/access tests
Rollout and recovery
Expose cancellation with retry-safe state transitions; retain pending cancellation during provider outages rather than claiming success.
Value of the work
For the engineer: Practice time modeling, conflict-safe booking, external state reconciliation, and credential lifecycle boundaries.
For the team: Review whether integration work protects appointment correctness and offers clear recovery when a provider is uncertain.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.