Security Warning: Client-Supplied Tenant IDs Are Not Authorization
A security article warns that using client-supplied headers like X-Tenant-Id for data scoping in multi-tenant APIs is insufficient. Accepting such an identifier without verifying the user's membership in that tenant creates an insecure direct object reference (IDOR) vulnerability. The article emphasizes that a valid authentication token only confirms identity, not organizational permissions. Developers are advised to perform server-side membership checks to authorize actions within a tenant. Client-provided tenant hints should be treated as untrusted input and either ignored or validated against known user permissions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in