Description
A profile or account API that uses a requester-supplied user ID without checking ownership or permissions can expose another user's data.
Potential impact
- Changing an ID in a URL or query may expose other users' personal, account, or payment information.
- Administrative data or internal identifiers may become visible to external users.
Remediation
Require authentication for profile requests and verify on the server that the requested ID belongs to the current user or that the caller has administrative permission.
Examples
Before
csharp
[HttpGet("profile/{id}")]
public IActionResult GetProfile(int id)
{
return Ok(repository.Find(id));
}
After
csharp
[Authorize]
[HttpGet("profile/{id}")]
public IActionResult GetProfile(int id)
{
if (id != CurrentUserId()) return Forbid();
return Ok(repository.Find(id));
}
Explanation:
- Before: A profile endpoint that accepts a user ID without authorization or ownership checks can disclose other users' records.
- After: The example permits only the authenticated user's own profile. The omitted
CurrentUserId()implementation must obtain its ID from the validated authenticated principal, not request input. If administrative access is needed, enforce a separate server-side authorization policy.