Context#
The subject is already authenticated; the failure is that the code path runs a sensitive operation (admin report, state change, export) without matching the subject’s role, scope, or tenant to the operation. Sibling object-level BOLA is a different class: the route is “right” in name, but the object id is wrong. This page is for function-level gaps.
Theory#
Common shapes: a new route ships without a guard the older pattern used; a GraphQL field resolver omits a field-level check the type-level assumes; a microservice trusts the internal network and skips entry authorization; a versioned path duplicates behavior with a weaker policy matrix. Fuzz by role matrix (low vs high privilege accounts) and by HTTP method and content type on the same path.
Practice#
Map route and role matrix in a lab#
- With two test accounts in different roles, call the same path and method with the same body shape. If one response is
403for the first account and200for the second on an admin-only function, the policy exists; if both return200, the function-level check is likely missing for that route set.
Compare gateway and app enforcement#
- When a gateway or BFF is in play, request the same internal route both through the gateway and (in a dev lab only) against a direct app port if exposed. A missing check often appears only on one path.
GraphQL field surface#
- List field names for a type in a test schema or doc bundle, then call each field with a low-privilege token. Field-level missing checks often show as
datafor fields that should beerrorswith an auth extension.
Tools#
- curl
- Postman
- Burp Suite