A push payload may reach a device outside the app’s visible page, and a system notification may appear on a lock screen. Transport encryption protects a message in transit but does not make its displayed text private from nearby people. Put only the minimum information needed for the alert in title and body. A notification click is navigation intent, not an authorization grant. The destination must load current server state under the current signed-in account; if access changed, show the normal denied or sign-in route without exposing a case title or note.
Private Notification Payload and Click Routing
Working case
An urgent assignment arrives for case 47. A detailed alert reading Damaged valve at named residence, assigned to reviewer 29 would reveal private facts on a shared tablet. The product instead displays New urgent assignment and an action to Open assignments. When clicked, the service worker focuses an existing authorized client or opens a safe application route. The page asks the server for the current assignment list. If reviewer 29 has signed out or lost the case, the route does not display the old details. The notification itself does not carry a signed download link.
Implementation boundary
function safeAlertPayload(event) {
if (event.kind !== "urgent_assignment") throw new Error("unsupported alert");
return { kind: event.kind, title: "New urgent assignment", route: "/assignments" };
}
console.log(JSON.stringify(safeAlertPayload({ kind: "urgent_assignment", caseTitle: "Private case 47" })));
// Output: {"kind":"urgent_assignment","title":"New urgent assignment","route":"/assignments"}Define a small allowlisted payload schema with a category, opaque notification ID, and safe route class. Reject arbitrary title, body, URL, and case-note fields from job producers. The service worker shows a user-visible notification and handles click through a vetted same-origin route; validate any stored path before opening it. Use notification tags or grouping carefully so one alert does not silently replace an unrelated urgent item. Fetch private detail only after the app is active and authenticated. Account changes should close or ignore stale notifications where the platform permits, but the server check remains the final boundary.
Cost and boundaries
A small payload lowers transfer and exposure; delivering n alerts still costs O(n) send attempts and can burden attention. Fetching details after click adds a network round trip, but ensures current authorization and content. Grouping can reduce notification count, yet over-grouping can hide separate urgent cases. Measure stale-click denials, lock-screen content review findings, notification count per shift, and whether reviewers reach the relevant inbox. Do not use click-through rate as proof that a confidential message was delivered safely.
Failure trace
A worker builds notification text from the raw case title, which includes a private person’s name. The server encrypts the payload, but the operating system displays that name on the lock screen. Move to an allowlisted generic message. Another click handler trusts a URL from the payload and opens an arbitrary destination. Restrict route classes and reauthorize on the destination. Test sign-out between send and click, a case reassignment, multiple accounts on one browser, and a stale notification after an export or deletion operation.
Verification
- No private case field appears in payload or visible notification text.
- Notification clicks lead to current server authorization.
- Unapproved destinations and payload fields are rejected.
Practice drill
Prepare an urgent case with a private title and note, then inspect the exact push payload and visible lock-screen text. Verify neither contains the private fields. Click while signed in, after sign-out, and after role revocation; each path should reach a current server decision. Attempt to inject an external URL and an unknown payload key, and verify the producer rejects both. Send two urgent items with the same tag and inspect whether the grouping rule preserves their meaning.
Decision note
Make the alert safe to display in public and treat clicks as untrusted routes back to current authorized state.
Common Mistakes
- Confusing transport encryption with lock-screen privacy.
- Using a notification click as access permission.
- Accepting an arbitrary destination URL from a job payload.
Connected lessons
Web Push and Notification Delivery; Notification Opt-In and Channel Preference; Push Subscription Account Binding and Rotation; Push Delivery Retries, Expiry, and Inbox Fallback; Object-Level Authorization for Reads and Writes; Browser Security and Data Stewardship; Route Scroll and Focus Restoration.
Apply and check
Build Project: private urgent assignment alerts and review Web Development: push notification decisions quiz.
