How to Verify Direct Link Access Is Denied
-
Sign in as any user role.

-
Copy the direct URL of a lease, property, or tenant that belongs to another account, and navigate to it while signed in as an unauthorized user.

-
Verify that middleware enforces role-based routing: a tenant cannot load
/dashboardor/landlord-dashboardroutes. -
Confirm that no partial data, titles, or snippets from the unauthorized record are visible in the response. [SCREENSHOT NEEDED HERE]
What to expect
Access is denied or a not-found response is returned. No data, titles, or partial snippets from the unauthorized record are displayed. Cross-role dashboard routes are redirected to the correct dashboard.
Need help?
| Symptom | Cause | Fix |
|---|---|---|
| Partial data visible after access denial | Backend returning non-empty response body with 403 | Verify Django REST framework returns generic message on PermissionDenied |
| User can access wrong role’s dashboard | Middleware prefix check not enforced | Verify middleware checks JWT role against dashboard prefix |
