Missing function-level access control

Missing function-level access control in C#

Description

Without effective authorization checks on administrative functions such as deleting users or accounts, ordinary users may be able to invoke them.

Potential impact

  • Attackers may delete or disable accounts or change permissions.
  • Administrative APIs exposed to external requests can lead to widespread account damage or service disruption.

Remediation

Apply Authorize to sensitive actions such as deletion, deactivation, and permission changes, and enforce role-based or policy-based authorization on the server.

Examples

Before

csharp
[HttpDelete("delete-user")]
public IActionResult DeleteUser([FromQuery] int id)
{
    return Ok();
}

After

csharp
[Authorize(Roles = "Admin")]
[HttpDelete("delete-user")]
public IActionResult DeleteUser([FromQuery] int id)
{
    return Ok();
}

Explanation:

  • Before: If authorization is not enforced at the action, controller, or global policy level, account-management operations may be exposed to unauthorized callers.
  • After: Require Authorize for destructive user or account-management operations and verify the caller's required role or policy before acting.

References