A report that joins tables can leak rows your list pages would hide

Chronological Source Flow
Back

AI Fusion Summary

Security vulnerabilities exist in reports and batch get-by-id endpoints where tenant and role filters are skipped. Reports joining tables can leak rows if per-table access filters are missing, causing summary cards to show unauthorized data. Similarly, batch endpoints may return records if a user provides specific IDs, bypassing list filters. To prevent these leaks, developers must apply the same read checks used in list and single-record endpoints to every table join and batch request.
Community Comments
Loading updates...
0