Read-only override

Context#

“Read only” in a generated client or in OpenAPI is not a server check. If the UserUpdate DTO in code still includes createdAt or creditScore in the bind set, a direct API call can set them.

Theory#

The same as mass assignment with a field that is documented as immutable. The offensive proof is a single PATCH with the supposedly read-only key.

Practice#

Send documented read-only fields on the write route#

  • In a lab, add id, createdAt, or a readOnlyFlag from the GET response into a PATCH body and see if the server accepts the write and reflects it on GET.

Tools#

  • curl
  • Burp Suite

Cookie Consent

We use cookies to enhance your experience. Learn more