Skip to content

Stateful / sequence BOLA (create-then-read-as-other) #18

Description

@PRAteek-singHWY

Create a resource as identity A (POST, behind --include-unsafe), capture the returned id, then attempt to read it as identity B — no pre-declared ownership required.

Files: src/engine/plan.ts, src/engine/replay.ts, src/engine/run.ts

Acceptance criteria

  • Opt-in only; safeguards documented.
  • Works against an extended mock server; tests included.

Comment /assign to claim.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ambitiousLarge / advanced taskenhancementNew feature or requesthelp wantedExtra attention welcome

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions