Description
Basing authorization on values users can modify, such as cookies or request parameters, may allow access controls to be bypassed.
Potential impact
An attacker may read another user’s data, access administrative functions or gain additional permissions.
Remediation
Retrieve roles and user identifiers from server sessions or server-side storage. Do not trust client-supplied values.
Examples
currentUserRoleFromDatabase() is an application function whose implementation is omitted. It must retrieve the role using the authenticated user’s server-side identity, not a user chosen by the request.
Before
php
<?php
if ($_COOKIE['user_role'] === 'admin') {
show_admin();
}
After
php
<?php
if (currentUserRoleFromDatabase() === 'admin') {
show_admin();
}
Explanation:
- Before: Bases authorization on cookies or other request data controlled by the client.
- After: Retrieves the role and user identity from server-side state instead of trusting client-supplied values.