Back to Lab
API SecurityhighCWE-639

IDOR in Task Resource

Insecure direct object reference on /tasks/:id allowed access to another user's tasks.

Problem

GET /tasks/:id fetched by ID without ownership check.

Discovery

Created two users; as user B, requested user A's task ID — returned 200 with data.

Impact

Confidential data exposure across accounts.

Remediation

Added middleware: verify JWT, then check task.ownerId === auth.userId before read/update/delete.

Retest

Replayed as user B — now 404 (not found) with no leakage; automated regression test added.

Lesson

Authorization must be per-resource, server-side; never rely on obscurity of IDs.