Context#
Approval bypass targets transitions that require a second principal (manager sign-off, risk review). Typical failures include self-approval (same user as requester and approver), reused approval tokens, weak binding of approval identifiers to the request payload, and routes such as POST /approve that omit role or organization checks.
Theory#
Map states (for example pending → approved → settled) and which credential may fire each transition. Overlap with Access control when the failure is a missing role on a route; this page emphasizes workflow graphs that include an explicit approver transition.
Practice#
Self-approval attempt#
- Create a request as user A, then call the approve endpoint authenticated as A when the product claims segregation of duties.
Replay stale approval id#
- Capture
approvalIdfrom a completed flow, start a new request, and substitute the oldapprovalIdif the server accepts it without binding to a new payload hash.
Tools#
- Burp Suite
- curl