Home Projects Portfolio Dashboard Export PDF Log in
JavaScript

Fixing Data Leakage: Filtering Inactive Records in User Profiles

One of the most subtle bugs you can encounter is a UI that displays information meant to be hidden. In the FotazaApp project, we recently discovered that user profile pages were exposing posts that had been marked as inactive or deleted.

The Discovery

While reviewing the data flow for user profile views, we noticed that the application was fetching the entire recordset associated with a user ID without applying a status filter. This led to a scenario where archived or soft-deleted content was still visible to the public, creating a mismatch between the database state and the frontend presentation.

The Refactor

To resolve this, we implemented a filtering layer that ensures only 'active' status records are returned to the client. Instead of relying on the database to return all records, we added a predicate check to the fetch logic.

Before

const getUserPosts = (userId) => {
  return db.posts.find({ userId });
};

After

const getUserPosts = (userId) => {
  return db.posts.find({ 
    userId, 
    status: 'active' 
  });
};

By enforcing this status constraint at the data-access layer, we guarantee that no matter which part of the application requests a user's post history, the output remains consistent and secure.

The Takeaway

Always treat your data-access layer as the primary defense against information leakage. When you add a new status or state to your models, ensure your queries are updated globally to reflect those business rules. Don't rely on the UI to hide what the API shouldn't have sent in the first place.


Generated with Gitvlg.com

Fixing Data Leakage: Filtering Inactive Records in User Profiles
T

Tomas Abatedaga Biole

Author

Share: