T09 · Insecure Skill Coding Practices
- Location
reference.md:136- Finding
Generated CRUD Controller Omits Authentication and Object-Level Authorization
- Content
View full analysis
ResponseBody { let db = request.db // 1. Fetch entity (with relationships if needed) guard let {entity} = try await {Entity}.query(on: db) .filter(\.$id == requestBody.{entity}Id) .with(\.$createdBy) // Add relationships as needed .first() else { throw Abort(.notFound, reason: "{Entity} not found: \(requestBody.{entity}Id)") } // 2. Perform the operation // {entity}.someField = requestBody.newValue // try await {entity}.save(on: db) // 3. Build and return ViewModel let viewModel = {Entity}ViewModel( id: try {entity}.requireID() // ... map fields ) return .init(viewModel: viewModel) } } ``` ### Technical Analysis The template retrieves an entity using an identifier supplied by the client: ```swift .filter(\.$id == requestBody.{entity}Id) ``` It then returns or potentially modifies that entity without requiring an authenticated principal or verifying ownership, tenant membership, role, or an operation-specific authorization policy. Loading the `createdBy` relationship does not itself enforce access control. This is an insecure default for generated read, update, or delete handlers. If an application does not independently enforce authorization through middleware or another mandatory layer, generated endpoints may be vulnerable to insecure direct object reference or broken object-level authorization. The project provides no evidence that authe ...[truncated 2496 chars]- Remediation
View remediation
