Assigning a task should check that the assignee can see it
Most "assign" endpoints check one thing: can the caller edit this task? If yes, PATCH /tasks/88 {"assignee_id": 512} goes through.
Nobody asks whether user 512 can see task 88. In a multi-tenant app t
authbyexample.hashnode.dev1 min read