Skip to content

other

Broken Object Level Authorization

An authorization flaw in which an API accepts a record identifier from the caller and reads or modifies that record without checking the caller is entitled to it.

Current clusters

build1 publisher

A generated read-then-write lets both requests spend the same balance

A dev.to walkthrough of AI-written Firebase code argues the dangerous defects sit in the architecture, and its examples are a balance update two concurrent requests can both pass and a rule that admits any signed-in user.

Publishers:dev.to

Reality

Evidence34
Adoption
Insufficient
Hype gap+22
Incentives
Insufficient
Confidence46