Skip to content

Tenant-scope pessimistic lock reads before acquiring database row locks #313

Description

@mforce

Parent: #244
Epic: #15
Severity: Low
Execution mode: AFK

What to build

Add AccountId to every raw SQL predicate that acquires a tenant-owned SalesOrder or InventoryItem row with FOR UPDATE. These queries bypass EF global filters and currently select by Id first, then perform an ownership check in application code. A caller with a foreign identifier can therefore touch or wait on another tenants row lock before receiving NotFound.

Keep the post-load ownership assertion as defense in depth and audit the repository for any other raw tenant-owned lock reads with the same pattern.

Acceptance criteria

  • SalesOrder and InventoryItem lock queries predicate on both Id and the resolved tenant AccountId before FOR UPDATE is acquired.
  • All parameters remain provider-parameterized; no interpolated SQL is introduced.
  • A repository-wide test or focused review accounts for every raw SQL query that bypasses global filters.
  • A cross-tenant integration test proves a foreign-id request returns NotFound without waiting on a lock held by the owning tenant.
  • Same-tenant parallel mutation and 409 concurrency behavior remain correct.

Blocked by

None.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:apiAPI/endpoint layerbugSomething isn't workingepic-1.5sliceThin vertical work item

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions