There is no page on authorization in apps: checking that every ID from a request belongs to (or is shared with) the caller (IDOR), and making sure admin-only actions aren't reachable through another route or API endpoint. Today it is one outdated sentence in prologue/security.rst.
There is no page on authorization in apps: checking that every ID from a request belongs to (or is shared with) the caller (IDOR), and making sure admin-only actions aren't reachable through another route or API endpoint. Today it is one outdated sentence in
prologue/security.rst.