Preserve tenant scope and conditional reads through the migration proxy
A local migration proxy forwards the account identifier but drops the authorized tenant context and If-None-Match value. The new path both loses cache semantics and trusts a tenant header supplied by the caller.
- Focused work estimate
- 2h 30m + prerequisites
- Priority in the scenario
- High
- Engineering practice
- Delegation boundaries · HTTP semantics · Authorization
Estimated field mix
- API design40%
- Security40%
- System design20%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Pattern topics
- ProxyRefactor
Keep access control and delegation transparent to the account contract while ensuring proxy forwarding cannot weaken tenant or cache semantics.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional B2B scheduling service stores account settings in a legacy module whose database access leaks into HTTP handlers. A replacement must support existing clients and migration by tenant. Build a local modular application, a synthetic two-tenant dataset, and controllable old/new adapters; no baseline repository or fixtures are supplied. Keep the exercise in one application and local database, with no live customer traffic.
Setup prerequisites
- REST contracts
- Tenant authorization
- Transactions
- Dependency injection
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
- PMIGRATE-101 · Put legacy account lookups behind a contract the replacement can keep
- PMIGRATE-102 · Remove the process-wide current-tenant account client
- PMIGRATE-103 · Separate account policy from legacy SQL and replacement storage
- PMIGRATE-104 · Shadow account reads without duplicating booking-channel writes
Acceptance criteria
- Forward server-derived tenant scope and conditional-read metadata through a typed proxy boundary without trusting caller-supplied scope.
- Preserve documented ETag, not-modified, not-found, and error behavior for both active implementations.
- Reject missing authorized scope before forwarding and keep proxy diagnostics free of credentials and full account bodies.
Implementation constraints
- The proxy controls access and delegation; keep storage mapping in adapters rather than accumulating business rules in the proxy.
Verification to include
- Send matching and stale ETags through old and new routes and compare their public conditional responses.
- Spoof a tenant header, omit authorized context, and force an adapter error; assert denial and sanitized error output.
Deliverables
- Proxy context contract and conditional-read/tenant regression cases
Rollout and recovery
Exercise the proxy with local synthetic clients before enabling tenant routing; route back through the corrected legacy boundary on failure.
Value of the work
For the engineer: Practice incremental migration, dependency boundaries, compatibility testing, and removing abstractions that obscure behavior rather than enabling change.
For the team: Inspect a migration plan with measurable parity, explicit write ownership, tenant-safe routing, and rollback limits instead of accepting a rewrite diagram alone.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.