Skip to content

Developer manual: no page on authorization (IDOR, admin-only routes) #15693

Description

@miaulalala

There is no page on authorization in apps: checking that every ID from a request belongs to (or is shared with) the caller (IDOR), and making sure admin-only actions aren't reachable through another route or API endpoint. Today it is one outdated sentence in prologue/security.rst.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions