PropurtiAcademypropurti.com

How to Verify PM Data Isolation

  1. Navigate to the sign-in page. PM data isolation verification

  2. In the Email address field, enter PM-A’s email address.

  3. In the Password field, enter PM-A’s password.

  4. Select Sign in. Access denied data isolation confirmation

  5. On the PM dashboard, verify that only PM-A’s properties, leases, and tenants are visible.

  6. Navigate directly to a PM-B property URL (for example, /dashboard/properties/[PM-B-property-id]).

  7. Verify that access is denied. No data, titles, or partial snippets from PM-B are visible. [SCREENSHOT NEEDED HERE]


What to expect

Only PM-A’s own properties, leases, and tenants are displayed. Attempting to access PM-B’s data via direct URL returns an access-denied or not-found response with no data leakage. Cross-role dashboard access is blocked.


Need help?

Symptom Cause Fix
PM-B’s data appears on PM-A’s dashboard Backend permission filter misconfiguration Verify can_access_property enforces property_manager_id == user.id
Direct URL to PM-B property shows data Permission check bypassed Verify Django permission class is applied to the endpoint