Sensitive data exposure on profile endpoint
The profile endpoint returns fields the requesting session is not authorised to read.
app/api/profile.py:64
source
GET /api/profile?id=2 → 200 with owner fields
runtime
session scope: user_id not enforced on lookup
auth
related: 2 endpoints share the lookup helper
related
Reproduction succeeded using a second authenticated session. The response contained fields belonging to a different account.