← All security rules
highCFG005· Authorization

Record fetched by ID without ownership check

A database row is looked up purely by an ID taken from the request (findUnique({ where: { id: params.id }})…) in a route with no ownership/authorization filter in the same query. Users can read or modify other users' records by guessing IDs (IDOR).

What the check contributes

Rule CFG005runs as part of CodeCordon's deterministic static-analysis pass. When it matches, the finding includes the source file, line number, severity, explanation, and a redacted snippet so the developer can inspect the evidence directly.

Recommended remediation

Scope queries to the authenticated user: WHERE id = ? AND user_id = ?. Centralize this in a data-access layer so no route can forget it.

How to use this result

  1. 1. Open the reported line. Confirm the match is active application code rather than a fixture, example, or false positive.
  2. 2. Apply the remediation in context. Preserve the intended behavior while removing the dangerous pattern.
  3. 3. Scan again. Verify the known pattern no longer appears, then continue with tests and any runtime or human security review appropriate to the application.

Limits of this check

A match is a review signal, not proof of exploitability. No match means only that this specific known pattern was not found in the applicable files. It does not rule out equivalent code, business-logic flaws, runtime vulnerabilities, or novel attack paths.

Related authorization checks

Check a public repository now

Run this rule together with the complete CodeCordon rule set. No account is required for a public-repository preview.

No account required. Public repositories only. Preview links expire after 24 hours.