Web Security / Thinking like a defender
Lesson 4 of 27
Broken access control
If changing /invoice/101 to /invoice/102 shows someone else's invoice, access control is broken. The server must check ownership for every object it returns.
Key points
- Check ownership on every request
- Hiding a button isn't protection
- Deny by default
@app.route("/invoice/<int:id>")
@login_required
def invoice(id):
inv = get_invoice(id)
if inv is None or inv.owner_id != current_user.id:
abort(404)
return render(inv)Quiz · +10 XP
What's the right fix when users can view others' records by changing an ID?
Log in to save progress and earn XP.