# Object-Level Authorisation and Data Exposure — API Design and Versioning

Source: https://www.geekswithgeeks.com/en/api-design/sec-object-level

> Prevent users reading or changing other users' objects and return only the fields they should see.

## Checking the ID is not enough

The most common serious API flaw is **broken object-level authorisation (BOLA)**, number one on the OWASP API Security Top 10: the API checks that you are logged in, but not that `GET /orders/1042` belongs to **you**, so changing the number reads someone else's order. For every request that takes an object ID, verify **on the server** that the caller may access **that object**. Also avoid **excessive data exposure**: return only the fields the client needs (never internal flags, password hashes or other users' personal data), use explicit response models rather than dumping database rows, and validate every input (type, range, length, allowed values). Prefer unguessable IDs (UUIDs) as defence in depth, but never as the only protection.

## The ownership check (illustrative)

The query itself includes the owner, so a wrong ID simply returns "not found" for other people's objects. Returning 404 (rather than 403) also avoids confirming that the object exists.

```python
@app.get("/v2/orders/{order_id}")
def get_order(order_id: str, user=Depends(current_user)):
    order = db.query_one(
        "SELECT id, total, status FROM orders WHERE id = %s AND owner_id = %s",
        (order_id, user.id),               # ownership is part of the query
    )
    if order is None:
        raise HTTPException(404, "Order not found")
    return order                           # only the fields we chose to expose
```

## Test with two accounts

Write tests that log in as user A and try to read, update and delete user B's objects. Every attempt must fail. This single test catches the most expensive class of API bugs.

**Quiz:** What does BOLA stand for and what is the flaw?

- [ ] A JSON format
- [ ] Better Online Load Analysis
- [ ] A caching feature
- [x] Broken object-level authorisation: accessing others' objects by changing an ID

*Answer:* Broken object-level authorisation: accessing others' objects by changing an ID. The server must check ownership of each object, not only that the user is logged in.
