Legal API: should respond 401 if wrong account is used to access data
Open
bug
Entities Team
Priority3
techdebt
- Dominant language
- JavaScript
- Stars
- 23
- Forks
- 62
- Avg merge
- 24m
- Merged PRs (30d)
- 1
Description
The legal API allows an account (eg, 668) to access business data from a different account (eg, 2288). This may be because both accounts as under the same login (BCREG0020).
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, endpoint, or entry points are named. Start by reproducing access with account 668 against account 2288 under the shared login BCREG0020, then trace the Legal API authorization path. Done means cross-account data access is rejected with HTTP 401 and the behavior is covered by an appropriate test.
Written by the indexing model from the issue text.
Assessment
- Domain
- api, authorization, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100