# IDOR and broken object authorization checklist

Inventory object references and compare operations across identities to find missing horizontal or vertical authorization checks.

## Recognition

- [ ] Requests contain numeric IDs, UUIDs, filenames, account names, nested object references, opaque tokens, or owner fields.
- [ ] The UI hides an operation but the endpoint remains callable.
- [ ] Responses differ when changing identity, method, path, body, content type, or object relationship.

## Manual workflow

- [ ] Use two controlled accounts and label every session clearly in the proxy.
- [ ] Create one object per account and record identifiers returned in paths, bodies, headers, links, and filenames.
- [ ] Build a matrix for read, list, create, update, delete, download, share, and administrative operations.
- [ ] Replay account A's request with account B's session while changing only the target object reference.
- [ ] Test nested IDs, secondary identifiers, batch endpoints, alternate methods, content types, and direct file URLs.
- [ ] Verify both the HTTP response and persistent side effect as the affected account.
- [ ] Test vertical access to administrator objects and functions without relying only on predictable IDs.

## Escalation

- [ ] Read or modify an administrator-owned object that exposes an administrator feature or secret.
- [ ] Use unauthorized sharing, ownership transfer, role update, or file access to cross the administrative boundary.
- [ ] Combine IDOR with stored content, file features, or server-side processing to reach another vulnerability class.

## Pitfalls

- [ ] Testing with only one account and assuming an object belongs to someone else.
- [ ] Changing the object ID and session at the same time, making the result ambiguous.
- [ ] Treating a 200 response as success without checking the returned object or side effect.
- [ ] Ignoring filenames, UUIDs, nested resources, and bulk operations because IDs are not sequential.

## Evidence

- [ ] Ownership setup for both accounts
- [ ] Original authorized request
- [ ] Single-variable unauthorized replay
- [ ] Victim-side verification
- [ ] Administrator objective

## Tools

- [ ] Burp/ZAP session labels and resend
- [ ] IDOR matrix
- [ ] Browser profiles or containers
- [ ] Response diff workbench

## Online references

- [PortSwigger IDOR and access-control labs](<https://portswigger.net/web-security/access-control/idor>)
- [OWASP authorization testing](<https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/05-Authorization_Testing/04-Testing_for_Insecure_Direct_Object_References>)

> Do you want to live curiously?
