A signed-in user could read another customer’s order by changing an id in the address bar
This endpoint looks up an order by the id in the URL and returns it without checking who is asking. Anyone with an account can put somebody else’s order id in and read the name, address and items on it. Order ids are sequential, so they do not have to guess.
// app/api/orders/[id]/route.ts export async function GET(request, { params }) { const order = await db.order.findUnique({ where: { id: params.id }, }); return Response.json(order);}Three lines either side of the match, with anything that looks like a secret removed before it is stored.
How to fix it
- Work out who is making the request on the server, from the session — not from anything in the URL or the request body.
- Add the owner to the query itself, so the database returns nothing when the order belongs to someone else.
- Answer “not found” rather than “not allowed”, so the response does not confirm that the order exists.
- Re-scan to confirm the finding is gone rather than assuming it is.
Technical detail
Broken object-level authorization, commonly written IDOR or BOLA. The handler performs a primary-key lookup with a client-supplied identifier and no ownership predicate, so authorization is missing rather than incorrect.
Rule authz/idor-route-param, matched on a route handler that reaches a data-access call with a path parameter and no tenant or owner constraint on the query.