One endpoint trusted an account ID straight from the URL. No token, no cookie, no ownership check — and the download links it handed back needed none either.
Blast radius
- One endpointthe defect itself
- Any account IDincremented by hand
- 95 customersa ceiling we chose, not a limit
- Anyone, for 7 dayslinks outlive the account that made them
- Authorize the object, not the route — ownership checked server-side on every fetch.
- Signed links measured in minutes, bound to the session that asked.
- Regression test: tenant A's session fetching tenant B's report must return 403.
Three changes. One sprint.
- GDPR Art. 32 security of processing, Art. 25 protection by design.
- Art. 33 notification assessment triggers if those reports carry non-public personal data.
- India DPDPA Sec. 8(5) reasonable security safeguards.
Ceiling: €20M or 4% of global turnover.
- The questionnaire answer, in one line: object-level authorization is enforced server-side and independently retested.
- Retest dated, signed, and attached to the claim — not a checkbox.
The reason the deal moves.
Watch the same finding reconstructed at the speed it happened — request, fan-out, and what survived the revoke.