Next.js App Router Auth Guard Auditor
When asked to update a user record, AI coding models regularly trust req.json().userId instead of reading from the authenticated session. That creates instant Insecure Direct Object Reference (IDOR) vulnerabilities where any user can edit anyone else's data. Paste your route below to audit your access guards.
route.ts or action)21 linesWhy AI Models Make the IDOR Mistake
When you ask an AI assistant to "build an endpoint that updates user profile details", it thinks like a frontend form designer. It creates a payload containing { userId: "123", email: "new@email.com" } and writes a database query updating whatever userId was sent.
Any teenager with curl or Postman can change that userId to yours and overwrite your data.
2 Authorization Flaws Detected
Review the failing access checks below and apply the fix prompt.
Server session verification detected in route handler.
Fix: Session is checked before handling request logic.
Route reads userId directly from user-controlled payload and uses it in database queries.
Fix: Never trust a userId passed in request bodies or query params. Derive the user ID from the verified server session (session.user.id).
Route returns the raw exception object in the response body. This leaks database schema and internal stack traces to attackers.
Fix: Log the error to console or telemetry, and return a generic error message string like "Internal server error".
Proper authorization status codes returned.
Fix: Verified.
Checking routes manually leaves holes. The Founder Pass ($15 one-time) checks your entire codebase for missing auth checks, insecure Supabase RLS policies, and leaked secrets.