Authorizationeasy0-2 years

An endpoint is behind a login, uses `@PathVariable Long id`, and looks up the order by that id alone. A pen test flags it as broken. The endpoint clearly requires authentication — so what's actually broken, and why does the fix belong in the query rather than after it?

Authentication answers "who are you"; authorization answers "may you do this" — and this endpoint only asks the first question. Requiring a login proves the caller is somebody, but nothing checks that the order belongs to them, so changing 42 to 43 in the URL reads another customer's data. This is broken object level authorization, and it's invisible to a test that just logs in and checks a 200. The fix is to make ownership part of the lookup itself — findByIdAndCustomerId(id, currentUser.getCustomerId()) — so there's never a moment where the object exists in a variable before the check has run, and a mismatch returns a 404 rather than a 403.

The lesson behind it →
More on Authorization