INNER CODE UNIT · Python

resolve_user

The-Art-of-Hacking/websploit · additional-labs/GraphQL/app.py:54

    def resolve_user(self, info, id):
        # Insecure Direct Object Reference (IDOR) equivalent in GraphQL
        # No auth check here!
        for user in users_db:
            if user["id"] == id:
                return User(
                    id=user["id"],
                    username=user["username"],
                    email=user["email"],
                    api_token=user["api_token"],
                    is_admin=user["is_admin"],
                    notes=user["notes"]
                )
        return None

    def resolve_users(self, info):
        # Returns all users but filters sensitive info in this view (mocking a "public" list)
        # But if they query 'user(id: "1")' directly, they get everything!

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…