# Cache Poisoning by Design

> A defect in which a cache key omits an input the entry depends on, so one request is served another's result.

Record: `architecture:cache-poisoning-by-design`
Kind: anti-pattern
Layer: [Enforcement Core](https://banes-lab.com/records/layer/enforcement-core.md)
Severity: discouraged
Scope: correctness_verification, security_governance
Canonical: https://banes-lab.com/ontology#architecture-cache-poisoning-by-design

Listed in [Architecture principles](https://banes-lab.com/api/records/architecture.md), after [N Plus One Query](https://banes-lab.com/records/architecture/n-plus-one-query.md) and before [Retry Storm](https://banes-lab.com/records/architecture/retry-storm.md).

## Repair

- Refactored by: define_cache_contract, include_context_in_key, key_by_input_fingerprint, add_invalidation, add_schema_version
- Detected by: cache_key_missing_user_or_tenant, cache_without_version, cache_keyed_by_time, no_invalidation, authorization_not_in_cache_key
- Violated by: Cache data without key correctness, tenant isolation, authorization context, invalidation, or schema version, or key the entry by time or lifetime alone.
- Measured by: cache keys missing tenant, identity or version
- Enforced by: cache-key review, tests that vary tenant and version

## Severity

- [discouraged](https://banes-lab.com/records/vocabulary/severity-discouraged.md)

## Category

- [Anti-patterns](https://banes-lab.com/records/architecture-category/anti-patterns.md)

## Force

- [Correctness verification](https://banes-lab.com/records/force/correctness-verification.md)
- [Security governance](https://banes-lab.com/records/force/security-governance.md)

## Negated by

- [Caching](https://banes-lab.com/records/architecture/caching.md)

## Linked from

- [Computation and resource](https://banes-lab.com/software-architecture/principles/computation-and-resource.md)
- [Anti-patterns](https://banes-lab.com/ontology/principles/architecture-category-anti-patterns.md)
- [Scalability / Performance / Optimization](https://banes-lab.com/ontology/principles/architecture-category-scalability-performance-optimization.md)
- [Failure shapes](https://banes-lab.com/ontology/reasoning/the-failure-shapes.md)
- [Severity levels](https://banes-lab.com/ontology/schema/the-vocabulary-severity.md)
- [The forces](https://banes-lab.com/ontology/schema/the-forces.md)
