AntiPattern

Misordered Authorization Hooks

post-provider-security-checks

Security checks run after authorization/provider logic, so side effects and decisions occur before DenyAccessListener can veto access; similarly, early null returns and per-call allocations undermine consistent authorization behavior and performance assumptions.