Skip to content

Conversation

@Elchi3
Copy link
Collaborator

@Elchi3 Elchi3 commented Oct 20, 2025

I'd like to propose to an add guideline about managing access to objects. Such access should be verified to prevent IDOR attacks.

I think it is more a security practice than a web platform security feature, so I put it in the second section. I will say that I don't understand why this document splits the guidelines in these two buckets (practices and features), and I also don't know if there is any order for the listings, so I just added this proposed guideline at the bottom.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant