Skip to Content
Security & privacyData access boundary

Developer reference

Data access boundary

Preserve API mediation, exact-origin checks and account retirement throughout financial UI flows.

Financial browser operations use /api/v1 and user-scoped services. A component must not introduce a direct financial table write to bypass a difficult API error.

Resource ownership

Resolve each account and semantic link under the authenticated user. An ID can identify a resource without authorizing access to it. Privileged server clients still need explicit user scoping.

API-token callers use registered method/scope checks. Unknown operations fail closed rather than becoming database access.

Request origin

Unsafe cookie-authenticated requests require the exact application origin. Validate actual authority and protocol, and keep forwarded-header behavior from expanding trust. Bearer integration access is a separate credential path, not a reason to relax browser cookies.

Browser retirement

Sign-out and account change clear private caches, owned pending drafts and stale UI generations. Late responses must not restore the previous user’s data. Dialogs, portals and guide coaches obey the same concealment lifecycle.

Failure behavior

A provider or database outage leaves an unavailable answer. It does not mean no accounts exist or all balances are zero. Do not reveal a retained private view while identity verification is uncertain.

Test direct API access, wrong-user IDs, denied scopes, logout, Back and different-account sign-in. See frontend providers and authentication.