A rate-limited public endpoint behind the /join page. The company is taken from the request host, so an application submitted on a builder's address is stamped with that builder's account. Approving or declining is admin-only and every update is filtered by both the request id and the caller's account.
Also called: join page · apply to join · crew application · someone requested access
- 1The public POST is IP rate-limited to five submissions per hour.
- 2The account is resolved from the subdomain; a submission with no tenant host is refused outright.
- 3The row is inserted with an explicit account id and a pending status.
- 4Listing is admin-only and filtered to the caller's account.
- 5Approve/decline updates filter by both id and account, so a cross-account attempt is a silent no-op that neither errors nor leaks existence.
The comment records what happened before the host was used: 'every form submission got the column-default org_default, so other tenants' Settings → Team surfaces would never have seen self-serve applicants AND a [default-tenant] admin would have seen everyone's applicants.' The apex submission is refused rather than defaulted for the same reason — 'without a tenant subdomain we don't know whose queue the application should land in.' The silent no-op on cross-account writes is deliberate: it 'doesn't 404, doesn't leak existence.'
- Applications submitted on any address were pooled into one account.
- One company's admin could see every other company's applicants.
- A guessed request id could be approved by an admin of a different company.
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →