Lazo Lab Sign up

Web Security / Thinking like a defender

Lesson 4 of 27

Broken access control

If changing /invoice/101 to /invoice/102 shows someone else's invoice, access control is broken. The server must check ownership for every object it returns.

Key points

  • Check ownership on every request
  • Hiding a button isn't protection
  • Deny by default
@app.route("/invoice/<int:id>")
@login_required
def invoice(id):
    inv = get_invoice(id)
    if inv is None or inv.owner_id != current_user.id:
        abort(404)
    return render(inv)
Watch a video on thisOpens YouTube search results for “Broken access control” in a new tab

Quiz · +10 XP

What's the right fix when users can view others' records by changing an ID?

Log in to save progress and earn XP.