Home/Tools/Next.js App Router Auth Guard Auditor
100% Free Developer Utility

Next.js App Router Auth Guard Auditor

When asked to update a user record, AI coding models regularly trust req.json().userId instead of reading from the authenticated session. That creates instant Insecure Direct Object Reference (IDOR) vulnerabilities where any user can edit anyone else's data. Paste your route below to audit your access guards.

Load sample:
Paste App Router handler (route.ts or action)21 lines

Why AI Models Make the IDOR Mistake

When you ask an AI assistant to "build an endpoint that updates user profile details", it thinks like a frontend form designer. It creates a payload containing { userId: "123", email: "new@email.com" } and writes a database query updating whatever userId was sent.

Any teenager with curl or Postman can change that userId to yours and overwrite your data.

2 Authorization Flaws Detected

Review the failing access checks below and apply the fix prompt.

Server Session Verification
PASSED

Server session verification detected in route handler.

Fix: Session is checked before handling request logic.

IDOR & User Impersonation Defense
VULNERABLE

Route reads userId directly from user-controlled payload and uses it in database queries.

Fix: Never trust a userId passed in request bodies or query params. Derive the user ID from the verified server session (session.user.id).

Error Sanitization & Stack Leakage
VULNERABLE

Route returns the raw exception object in the response body. This leaks database schema and internal stack traces to attackers.

Fix: Log the error to console or telemetry, and return a generic error message string like "Internal server error".

HTTP Status Code Discipline
PASSED

Proper authorization status codes returned.

Fix: Verified.

Want all your API routes and database tables audited?

Checking routes manually leaves holes. The Founder Pass ($15 one-time) checks your entire codebase for missing auth checks, insecure Supabase RLS policies, and leaked secrets.