SShortSingh.
Back to feed

Security Warning: Client-Supplied Tenant IDs Are Not Authorization

0
·3 views

A security article warns that using client-supplied headers like X-Tenant-Id for data scoping in multi-tenant APIs is insufficient. Accepting such an identifier without verifying the user's membership in that tenant creates an insecure direct object reference (IDOR) vulnerability. The article emphasizes that a valid authentication token only confirms identity, not organizational permissions. Developers are advised to perform server-side membership checks to authorize actions within a tenant. Client-provided tenant hints should be treated as untrusted input and either ignored or validated against known user permissions.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

New Windows tool mounts WebDAV and NAS storage as local drive letters

Developer ScsDriver has created a lightweight Windows tool that allows users to mount WebDAV servers and NAS storage as local drive letters. The software offers unlimited mounts, automatic reconnection at startup, and HTTPS encryption for secure connections. It is available in English and Chinese for $2 monthly or $9.99 annually, which the creator states is cheaper than competitors like NetDrive and Mountain Duck. The tool aims to provide a simple, native drive experience without bloatware or ads. It targets developers, NAS users, and those dissatisfied with existing WebDAV clients.

0
ProgrammingDEV Community ·

Google Play mandates 14-day closed test with 12 opt-in testers for new personal accounts

Google now requires personal developer accounts created after November 13, 2023, to conduct a closed test before publishing apps. The mandatory test must have at least 12 unique testers actively opted in for 14 consecutive days. The test resets if a tester leaves or the number drops below 12, with Google monitoring opt-in status, not installs. After testing, developers must complete a production access questionnaire, which is usually reviewed within a week.

0
ProgrammingDEV Community ·

OLSRT: A C11 concurrency runtime with actors, channels, and event loop released

OLSRT is a new Apache-2.0 licensed C11 runtime library designed for concurrent programming on Linux and other systems. It consolidates common concurrent programming components like actors, channels, promises, and an event loop into a single package. The library is written in plain C11 with no external dependencies beyond pthreads and the standard library. Its developers recently fixed eleven significant bugs discovered after adding a comprehensive test suite, improving the runtime's reliability. The project includes several demonstration programs showcasing its core features and performance characteristics.

0
ProgrammingDEV Community ·

Photos can leak home GPS coordinates via hidden metadata, JavaScript fix exists

Smartphones embed hidden EXIF metadata in photos, including precise GPS coordinates, device details, and timestamps. This data can reveal exact home addresses and daily routines when original photos are shared online. The article explains the technical structure of JPEG files where this metadata is stored. It proposes a client-side JavaScript solution using HTML5 Canvas to strip EXIF data without uploading images to external servers. This approach preserves privacy by removing location and device information before sharing.