What is IDOR, and does my app have it?
IDOR, insecure direct object reference, means the app returns or changes a record based on its ID without checking the record belongs to the person asking. Change /invoices/1041 to /invoices/1040 and you see someone else's invoice. It is the most common serious finding in AI-built apps, because the page only asks for your records while the endpoint behind it will return anyone's.
What it looks like
The page calls GET /api/orders/1041. The endpoint loads order 1041 and returns it. It checks you are logged in. It does not check order 1041 is yours. Any logged-in user can loop through IDs and download every order. Unguessable IDs such as UUIDs slow this down; they do not fix it, because IDs leak in URLs, emails and shared links.
How to test for it
- Create two accounts and some data in each.
- In the browser developer tools, watch the network requests as account A uses the app.
- Replay requests from account A with account B's record IDs.
- Try reads, updates and deletes.
- Any success is a finding.
The fix
Every query that loads a record filters by the caller: where id = ? and owner_id = session.user, or the equivalent row level security policy. The owner comes from the session, never from the request. In multi-tenant apps, filter by organization as well. See keeping customers' data separate.
Do unguessable IDs help?
Switching from sequential numbers to UUIDs makes it harder to enumerate every record, and it is worth doing. It is not a fix. IDs appear in shared links, emails, browser history, logs, screenshots and support tickets, and a former team member keeps every ID they ever saw. A user who obtains one ID can still fetch that record if the server does not check ownership.
The fix is always the ownership check on the server or in database rules. Treat UUIDs as an extra layer that slows mass scraping, not as access control. When a tester reports an IDOR, they will usually show it with IDs gathered from legitimate use of the app, precisely to demonstrate this.
Getting it checked
TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Is IDOR the same as broken access control?
It is one kind. Broken access control, first on the OWASP Top 10 for web applications, also covers users reaching admin functions and similar.
Does using Supabase protect me from IDOR?
Only if row level security policies restrict each row to its owner. Without them, the public API is an IDOR on every table.