Many multi-tenant APIs accept X-Tenant-Id, org_id, or a similar field from the client and then scope queries to that value. Trusting the client's chosen tenant is not authorization. An authenticated user can send any tenant id they like. If you load data for that id without proving the subject is a member (or otherwise related) to that tenant, you... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
A client-supplied tenant id is not authorization
Many multi-tenant APIs accept X-Tenant-Id, org_id, or a similar field from the client and then scope queries to that value. Trusting the client's chosen tenant…