A new field user with no boards assigned saw every board
Two new field staff were given no boards and could see all 101. A week later a user with 51 boards was shown 123 due out of 128. Two causes, one fix.
Topic
Permissions, isolation, credentials, and failures that stay quiet.
24 articles
The security writing here is shaped by having cleaned up after a real compromise rather than by a framework. The lesson that keeps recurring is that the failures which matter are the quiet ones: a backup that has been failing for four days, a permission model that a CSV export walks straight past, an audit log with a bucket of events nobody has ever looked in.
Detection by pattern matching is treated with suspicion throughout, for a specific reason — signature scanning found nothing on a site that turned out to hold two hundred and eleven malicious files, and file-integrity comparison against the official distribution found them all. Attackers write code to defeat patterns. They do not rewrite the upstream release.
Two new field staff were given no boards and could see all 101. A week later a user with 51 boards was shown 123 due out of 128. Two causes, one fix.
A manager who should see 33 people could reach 726 and export 15,452 rows. An empty team also meant no limit at all. How it was found and closed.
A hire business relied on its audit trail. It held nothing for ID, bank and odometer changes, and no row for 1,231 vehicle documents. Two quiet faults.
A login that failed at random hid a worse fault: the site served a logged-in administrator's page to anyone. Fifty-six emails were stuck as well.
The crew who mount and photograph boards could open Billing and read client rates. Removing the permission revoked nothing, and the next fix would have erased data.
Cleaning up and adding security plugins kept us maintaining a position. Rebuilding our own site as static pages removed what there was to attack.
The complaint was that the target screen was unfriendly. Underneath it, the save endpoint checked nothing and 866 of 877 targets were in the wrong units.
If staff can ask an AI about company data, what stops it answering the wrong person? Not a sentence telling it to behave. Where the refusal has to live.
A test harness could not photograph one screen, on purpose. It shows the credential that pairs a tablet to a child, and that changes how it is stored.
A pricing panel asked for one customer's agreed prices and got every customer's. Nothing failed or warned. How far it went, and how we closed it.
A login endpoint with no credential was fenced off by an assert. One optimisation flag strips every assert from the build, and the fence with it. Caught in review.
A compliance portal let staff see their own certificates, but a read-only role could see everyone's, and the protection rests on copied lines.
A no-login quote link is a second way for your costs to reach a customer. We built it on the same stripping as the PDF, then the client asked us to remove it.
A view over tables protected by row-level security ran with its owner's rights and would have summed every tenant's receivables. Caught before any customer saw it.
A clerk allowed only to upload spreadsheets could create customers and products she could not create by hand. And one bad row could stop the whole upload.
An API client generated from a live schema guessed which credential each route needed from its path prefix, and got one pair backwards. It failed safe.
Signing out of this compliance system changed nothing on the server. A copied login stayed good for eight hours, and access changes left no trail for an auditor.
An audit trail hid the request but stored old and new password values in clear, then showed a password change as no change. Both faults and the fixes.
A sales rule checked that a site had a till but skipped the check for account owners, so a sale could be booked and stock taken from a production store.
A site was cleaned several times and kept being reinfected while the scanner reported clean. Comparing every file with the official release found 211 files.
One website on a shared server was hacked, and every site on it fell because they all used the same database password. Why reuse removes your defences.
Several websites ran as one user on one server. When one was hacked, all were, and the security plugins were doing nothing. What separating them changed.
Every screen limited a branch manager to their own branch. The report export did not, so one click produced the whole company's customers and payments.
A branch check compared two different kinds of value and denied everyone. Fixing it led to 37 actions a branch user could have taken on other branches' records.