User-controlled authorization checks

User-controlled authorization checks

Description

Basing authorization on values users can modify, such as cookies or request parameters, may allow access controls to be bypassed.

Potential impact

An attacker may read another user’s data, access administrative functions or gain additional permissions.

Remediation

Retrieve roles and user identifiers from server sessions or server-side storage. Do not trust client-supplied values.

Examples

currentUserRoleFromDatabase() is an application function whose implementation is omitted. It must retrieve the role using the authenticated user’s server-side identity, not a user chosen by the request.

Before

php
<?php
if ($_COOKIE['user_role'] === 'admin') {
    show_admin();
}

After

php
<?php
if (currentUserRoleFromDatabase() === 'admin') {
    show_admin();
}

Explanation:

  • Before: Bases authorization on cookies or other request data controlled by the client.
  • After: Retrieves the role and user identity from server-side state instead of trusting client-supplied values.

References