Authorization must follow the resource
Hiding a menu item is useful interface behavior, but it is not authorization. Every read and update needs to verify the actor, workspace membership, permission, resource owner, and current state on the server.
A well-designed repository is workspace-scoped by default. A request for an object in another workspace should look like a missing object, not reveal that the identifier exists.
Destinations need strict parsing
A destination should use an allowed scheme, include a valid host, and exclude embedded credentials. Private, loopback, link-local, and internal destinations deserve explicit rejection in workflows that might later fetch or inspect the URL.
Normalization should be predictable. Removing fragments from server-side redirects and lowering the host prevents small formatting differences from creating operational confusion.
Failure should be safe and honest
A redirect path must not guess when its routing projection is unavailable. An API should return structured problem details with a request identifier, while sensitive internal details remain in protected logs.
Rate limits, bounded request bodies, timeouts, reserved routes, and idempotency are not secondary polish. They define how the system behaves under retries, mistakes, and deliberate abuse.