noCV
FORM-108 · Make approval trustworthy

Retire approval controls when authority changes

Practice briefBugIntermediate

An approver leaves the page open past delegation expiry. Approve fails, but controls remain active and the page incorrectly labels the request handled.

Focused work estimate
1h 30m + prerequisites
Priority in the scenario
High
Engineering practice
Authorization UX · Tenant isolation · Error handling

Estimated field mix

  • Frontend60%
  • Security40%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

The fictional Beacon operations team buys equipment through a browser form. Finance checks totals, departments, and quotes. Scope is one currency per request and an approval API contract; payments and accounting integration are excluded.

Setup prerequisites

  • Synthetic department and cost-center directory
  • Draft, submission, and approval API fixtures

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Denial preserves request state and removes stale controls after authority refresh.
  • Organization switching clears previous request and permissions before rendering new context.
  • Access-loss messages omit private authorization diagnostics.

Implementation constraints

  • UI checks improve interaction; the API must authorize every action independently.

Verification to include

  • Approve with current authority and display only the confirmed result.
  • Expire delegation and switch organizations mid-request; no success state or old request content appears.

Deliverables

  • Authority-refresh handling and denied-approval browser case

Rollout and recovery

Release denial handling independently; disable approvals separately while preserving permitted reading.

Value of the work

For the engineer: Practice form modeling, exact totals, revision handling, and collaboration under failure.

For the team: Inspect whether a developer protects business workflows from duplicate, lost, or misleading submissions.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.