← ClaudeAtlas

hunting-mass-assignment-and-property-authzlisted

Hunt mass assignment and broken object-property authorization: handlers that bind a client request payload straight onto a record or model and let the caller write fields it should never control - role, is_admin, owner_id, tenant, price, balance, verified, status, or another user's foreign key. Covers auto-binding and hydration that take the whole payload, blocklist filters that miss a field, nested and relation fields that reopen the hole, type juggling that flips a flag, and read paths that return properties the caller should not see. Use when reviewing any create or update handler that maps request fields onto a persisted object. The payload field is the source, the record write is the sink, and the server-controlled property is the bug.
UnboundCompute/security-agent-skills · ★ 4 · AI & Automation · score 80
Install: claude install-skill UnboundCompute/security-agent-skills
# Hunting mass assignment: which fields, not which object Broken object-level authorization asks whether the caller may reach *this object*. Mass assignment asks the next question: given an object the caller may write, which of its *fields* may they set? The bug is a handler that binds a request payload onto a record and trusts the client to send only the fields it should, so an attacker adds `"role":"admin"`, `"owner_id": <someone else>`, `"price": 0`, or `"verified": true` to a payload the endpoint was never meant to accept, and the framework writes it. You find it by listing what the client can put into the payload, following it to the record write, and asking which of those fields the server, not the client, is supposed to own. ## When to use - You are reviewing a create or update handler that maps request fields onto a persisted object. - The framework auto-binds or hydrates a payload onto a model, struct, or record. - Some properties of the object are meant to be server-controlled: privilege, ownership, tenancy, money, state, or verification flags. ## Scope check Test property writes only in systems you own or are authorized to test, with accounts that let you observe a privilege, ownership, or state change take effect. If you can't name the authorization, stop. ## The loop 1. **List the writable fields the client can reach.** For each create and update handler, determine how the payload becomes a record: an explicit field-by-field assignment, an allowl