A push subscription contains an endpoint and encryption material for one service-worker registration. The endpoint is a delivery capability and should be handled as a secret, not logged in a page URL or treated as a public user ID. The browser sends subscription data to the application server after a signed-in, protected registration request. The server binds it to the current actor, tenant, device record, and enabled alert category. Subscriptions can expire or change, and a device can switch accounts. Rotation, logout, revocation, and invalid endpoint responses need defined cleanup paths.
Push Subscription Account Binding and Rotation
Working case
Reviewer 29 enables urgent alerts on a shared tablet while signed into organization 6. Later reviewer 62 signs in on the same browser. If the server associates the old endpoint with both accounts, reviewer 62 may see a lock-screen alert about reviewer 29’s case 47. The app unbinds or deactivates the old account’s subscription during sign-out and requires a new authorized registration for reviewer 62. A stale endpoint returned by the push service is removed rather than retried forever. A subscription-change event may help repair state, but account binding remains a server-owned check.
Implementation boundary
function subscriptionOwnerMatches(actor, binding) {
return actor.userId === binding.userId && actor.tenantId === binding.tenantId && binding.active;
}
console.log(subscriptionOwnerMatches({ userId: 62, tenantId: 9 }, { userId: 29, tenantId: 6, active: true }));
// Output: falseCreate a server endpoint that accepts the browser subscription only under authenticated actor and tenant context. Protect the write against cross-site request forgery and validate the endpoint shape and encryption-key fields without trusting client-supplied user or tenant IDs. Store the subscription encrypted or otherwise protected under the product threat model, and limit staff access to it. Keep one stable device record or subscription fingerprint for idempotent updates while avoiding full endpoint values in ordinary logs. On account switch, logout, permission loss, or push-service invalidation, mark the old binding inactive. Rotate application-server signing keys deliberately and plan how existing subscriptions will be renewed.
Cost and boundaries
A subscription lookup by account and device should be O(1) with suitable indexes, while sending to d devices costs at least O(d) delivery attempts. Keeping stale endpoints wastes storage and push-service requests. Key rotation can create a burst of resubscriptions and failed deliveries, so measure active and invalid endpoint counts. A subscription endpoint has high sensitivity even though it is not a password; limit retention and audit access. Device cleanup is extra work, but it prevents account crossover on shared browsers.
Failure trace
A client POST contains userId 29 and tenantId 6, and the server trusts those fields while saving the endpoint. A signed-in user can bind a different account to a device. Derive identity from the verified session and reject forged scope. Another failure logs the entire subscription in a request trace; a copied endpoint can be misused for delivery. Redact the capability. Test repeated registration, shared-device account switch, role removal, invalid endpoint response, and a subscription that changes while a tab is closed.
Verification
- A forged account field cannot change a subscription owner.
- Shared-browser account switching disables the old binding.
- Logs and public URLs contain no subscription endpoint.
Practice drill
Register a subscription for reviewer 29 and organization 6. Repeat the same request, then forge reviewer 62 and tenant 9 fields; verify the server retains only trusted identity and does not duplicate the device record. Sign out and in as reviewer 62, send an alert for case 47, and confirm the old binding is ineligible. Simulate endpoint expiry and application-server key rotation. Inspect logs for endpoint and encryption material leakage.
Decision note
Bind subscription capabilities to current server-trusted identity and retire them when device, permission, or account state changes.
Common Mistakes
- Using a client user ID as authority for subscription ownership.
- Logging the full endpoint as a harmless URL.
- Retrying invalid endpoints indefinitely.
Connected lessons
Web Push and Notification Delivery; Notification Opt-In and Channel Preference; Private Notification Payload and Click Routing; Push Delivery Retries, Expiry, and Inbox Fallback; Sessions and CSRF: keep identity on the server; Permission Revocation and Active Sessions; Browser Storage Cleanup on Account Change.
Apply and check
Build Project: private urgent assignment alerts and review Web Development: push notification decisions quiz.
