Record fetched by ID without ownership check
A database row is looked up purely by an ID taken from the request (findUnique({ where: { id: params.id }})…) in a route with no ownership/authorization filter in the same query. Users can read or modify other users' records by guessing IDs (IDOR).
What the check contributes
Rule CFG005runs as part of CodeCordon's deterministic static-analysis pass. When it matches, the finding includes the source file, line number, severity, explanation, and a redacted snippet so the developer can inspect the evidence directly.
Recommended remediation
Scope queries to the authenticated user: WHERE id = ? AND user_id = ?. Centralize this in a data-access layer so no route can forget it.
How to use this result
- 1. Open the reported line. Confirm the match is active application code rather than a fixture, example, or false positive.
- 2. Apply the remediation in context. Preserve the intended behavior while removing the dangerous pattern.
- 3. Scan again. Verify the known pattern no longer appears, then continue with tests and any runtime or human security review appropriate to the application.
Limits of this check
A match is a review signal, not proof of exploitability. No match means only that this specific known pattern was not found in the applicable files. It does not rule out equivalent code, business-logic flaws, runtime vulnerabilities, or novel attack paths.