noCV
PMIGRATE-105 · Compare and route deliberately

Preserve tenant scope and conditional reads through the migration proxy

Practice briefBugIntermediate

A local migration proxy forwards the account identifier but drops the authorized tenant context and If-None-Match value. The new path both loses cache semantics and trusts a tenant header supplied by the caller.

Focused work estimate
2h 30m + prerequisites
Priority in the scenario
High
Engineering practice
Delegation boundaries · HTTP semantics · Authorization

Estimated field mix

  • API design40%
  • Security40%
  • System design20%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Pattern topics

  • ProxyRefactor

    Keep access control and delegation transparent to the account contract while ensuring proxy forwarding cannot weaken tenant or cache semantics.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional B2B scheduling service stores account settings in a legacy module whose database access leaks into HTTP handlers. A replacement must support existing clients and migration by tenant. Build a local modular application, a synthetic two-tenant dataset, and controllable old/new adapters; no baseline repository or fixtures are supplied. Keep the exercise in one application and local database, with no live customer traffic.

Setup prerequisites

  • REST contracts
  • Tenant authorization
  • Transactions
  • Dependency injection

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Forward server-derived tenant scope and conditional-read metadata through a typed proxy boundary without trusting caller-supplied scope.
  • Preserve documented ETag, not-modified, not-found, and error behavior for both active implementations.
  • Reject missing authorized scope before forwarding and keep proxy diagnostics free of credentials and full account bodies.

Implementation constraints

  • The proxy controls access and delegation; keep storage mapping in adapters rather than accumulating business rules in the proxy.

Verification to include

  • Send matching and stale ETags through old and new routes and compare their public conditional responses.
  • Spoof a tenant header, omit authorized context, and force an adapter error; assert denial and sanitized error output.

Deliverables

  • Proxy context contract and conditional-read/tenant regression cases

Rollout and recovery

Exercise the proxy with local synthetic clients before enabling tenant routing; route back through the corrected legacy boundary on failure.

Value of the work

For the engineer: Practice incremental migration, dependency boundaries, compatibility testing, and removing abstractions that obscure behavior rather than enabling change.

For the team: Inspect a migration plan with measurable parity, explicit write ownership, tenant-safe routing, and rollback limits instead of accepting a rewrite diagram alone.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.