Developer reference
Data access boundary
Preserve API mediation, exact-origin checks and account retirement throughout financial UI flows.
Financial browser operations use /api/v1 and user-scoped services. A component must not introduce a direct financial table write to bypass a difficult API error.
Resource ownership
Resolve each account and semantic link under the authenticated user. An ID can identify a resource without authorizing access to it. Privileged server clients still need explicit user scoping.
API-token callers use registered method/scope checks. Unknown operations fail closed rather than becoming database access.
Request origin
Unsafe cookie-authenticated requests require the exact application origin. Validate actual authority and protocol, and keep forwarded-header behavior from expanding trust. Bearer integration access is a separate credential path, not a reason to relax browser cookies.
Browser retirement
Sign-out and account change clear private caches, owned pending drafts and stale UI generations. Late responses must not restore the previous user’s data. Dialogs, portals and guide coaches obey the same concealment lifecycle.
Failure behavior
A provider or database outage leaves an unavailable answer. It does not mean no accounts exist or all balances are zero. Do not reveal a retained private view while identity verification is uncertain.
Test direct API access, wrong-user IDs, denied scopes, logout, Back and different-account sign-in. See frontend providers and authentication.