Back to Lab
API SecurityhighCWE-639
IDOR in Task Resource
Insecure direct object reference on /tasks/:id allowed access to another user's tasks.
Problem
GET /tasks/:id fetched by ID without ownership check.
Discovery
Created two users; as user B, requested user A's task ID — returned 200 with data.
Impact
Confidential data exposure across accounts.
Remediation
Added middleware: verify JWT, then check task.ownerId === auth.userId before read/update/delete.
Retest
Replayed as user B — now 404 (not found) with no leakage; automated regression test added.
Lesson
Authorization must be per-resource, server-side; never rely on obscurity of IDs.