Preparing the next view without exposing private workflow data.
Engineering task library · Version 5
Work that feels like work.
Design a system. Diagnose tail latency. Ship a migration. Recover a failed rollout. Pick a focused ticket or follow a project through its delivery phases.
The portal has three roles, but engineers infer permissions from page names. A read-only agent can discover an Edit route that was added for partner administrators.
Changing partnerId in the purchase-order query reveals another partner's orders. The controller authenticates the session but trusts the query filter to choose the tenant.
A batch update contains nine permitted order IDs and one foreign ID. The service updates the first nine before discovering the forbidden order and returning 403.
A foreign document request returns Forbidden: invoice-acme-september.pdf. Download is blocked, but the error itself leaks the other partner's filename.
Two acceptance requests use the same invitation token at nearly the same time. The portal creates duplicate memberships and occasionally accepts a token after its role was revoked.
A partner creates a read-only reporting key while an administrator is logged in. Requests using that key inherit the administrator's full session permissions.
An administrator starts a large partner export and loses membership while it runs. The worker later emails a long-lived storage URL using authorization captured only at request time.
A partner administrator is downgraded to read-only but retains edit access on one API instance for an hour because permission caches are local and keyed only by user ID.
Security receives Denied entries with no action name, while application debug logs include complete document metadata. Neither source is suitable for reviewing a partner complaint.
A buyer is removed from a partner while their order-approval request is between authorization and commit. The current implementation commits the approval after removal without a defined policy.
Operations knows the supplier key is used by the API but discovers a nightly worker still reads an old environment variable. Rotation planning has no reliable consumer list.
API and worker read process environment independently and cannot report which credential version they are using. The test suite also embeds key values in request snapshots.
Constrain support elevation and preserve trustworthy audit records.
10 tickets · 3 phases
Take the brief into your own workflow.
For engineers
Practice scoped changes, keep a portable implementation and verification record, and learn to explain operational tradeoffs. Choose a ticket whose prerequisites you can provide.
For companies
Use realistic work to structure onboarding, internal practice, and conversations about engineering decisions. Each project names the delivery benefit. Agree scope and compensation before requesting company-specific work.
CSV contains one row per ticket. Map fields and issue types in your tracker; project grouping and dependency keys are descriptive. JSON preserves the complete project structure. These downloads do not synchronize with Jira.