How to Verify Landlord Data Isolation
-
Navigate to the sign-in page.

-
In the Email address field, enter Landlord-A’s email address.
-
In the Password field, enter Landlord-A’s password.
-
Select Sign in. [SCREENSHOT NEEDED HERE]
-
Navigate directly to a Landlord-B property URL (for example,
/landlord-dashboard/properties/[Landlord-B-property-id]). -
Verify that access is denied and no data from Landlord-B is visible. Confirm that middleware blocks any cross-role dashboard access. [SCREENSHOT NEEDED HERE]
What to expect
Landlord-A can only view their own properties. Attempting to access Landlord-B’s property via direct URL is denied. Cross-role dashboard routing is blocked by middleware.
Need help?
| Symptom | Cause | Fix |
|---|---|---|
| Landlord-B’s property appears for Landlord-A | Permission check not enforced | Verify can_access_property checks landlord_id == user.id |
| Landlord dashboard accessible by other roles | Middleware role check bypassed | Verify getRoleDashboardPrefix returns /landlord-dashboard for landlord role |
