How isolation works
- Every authenticated request re-resolves the user from the database, and the active organization (
req.org) is always one the caller belongs to - it can never be switched to an unrelated organization. - Public API keys and
pos_...tokens map to exactly one organization. - Repository methods are scoped by
organizationId; cross-organization lookups require an explicit org filter. - Media, posts, webhooks, and credentials carry an
organizationIdand are queried with it. - Shared post previews are gated by a random share token rather than a guessable id.
Self-hosted caveat
When billing is disabled (noPOLAR_ACCESS_TOKEN), plan and role policy checks are bypassed, and every member effectively has broad access. On such instances the USER role is not a security boundary - rely on trusted members instead. Managed Cloud billing keeps the role model enforced.
