Description
Without effective authorization checks on administrative functions such as deleting users or accounts, ordinary users may be able to invoke them.
Potential impact
- Attackers may delete or disable accounts or change permissions.
- Administrative APIs exposed to external requests can lead to widespread account damage or service disruption.
Remediation
Apply Authorize to sensitive actions such as deletion, deactivation, and permission changes, and enforce role-based or policy-based authorization on the server.
Examples
Before
csharp
[HttpDelete("delete-user")]
public IActionResult DeleteUser([FromQuery] int id)
{
return Ok();
}
After
csharp
[Authorize(Roles = "Admin")]
[HttpDelete("delete-user")]
public IActionResult DeleteUser([FromQuery] int id)
{
return Ok();
}
Explanation:
- Before: If authorization is not enforced at the action, controller, or global policy level, account-management operations may be exposed to unauthorized callers.
- After: Require
Authorizefor destructive user or account-management operations and verify the caller's required role or policy before acting.