HDDS2402 · L05 · UNASSESSED BROWSER PRACTICE

LendLab: follow one request

A borrower may read their own loan. The public catalogue shows equipment and availability, with one to three items per request. Start with what should happen, then change one condition and inspect the response.

All names and records are synthetic. The actor selector chooses a classroom fixture that stands in for an already validated session; it is not a real login.

01 · NORMAL SERVICE AND RECORD PERMISSION

Who may read this loan?

Mina → loan 73 · CameraLeo → loan 74 · Projector

Predict first. Keep the actor, change the record, then explain which relationship changed. Swap the driver and observer.

No request yet.

The observed response will appear here.

Does changing a borrower claim change the actor? Which fields must be absent from a refused response? Inspect the same request in DevTools → Network → Headers and Response.

02 · RETURNED FIELDS AND INPUT LIMITS

What should the public catalogue disclose?

Public readers need an item name and availability. Contact details and internal staff notes are unnecessary for this purpose.

No request yet.

The observed response will appear here.

Predict the boundary cases. Compare the actual field names and item count with the intended rule. Does a valid count establish permission to somebody else’s loan?