Assigning a task should check that the assignee can see it
Most "assign" endpoints check one thing: can the caller edit this task? If yes, PATCH /tasks/88 {"assignee_id": 512} goes through.
Nobody asks whether user 512 can see task 88. In a multi-tenant app the assignee picker usually filters by workspace, but the API often takes any user id it's given. So a crafted request can assign a private task to someone outside the project, or outside the tenant. Then the assignment email, the "assigned to me" list, and the mobile push all show that person a title and description they were never allowed to read.
Check the assignee on the server. Before saving, run the same read check you'd run if user 512 opened /tasks/88 themselves, and reject the request with a 422 if it fails. Do the same for watchers, reviewers, and any other field that holds a user id and causes the app to show that user the record.
To test it, create a private project, then send the assign request with a user id from a second workspace. If it saves, the check is missing.
