Most apps have a little search box for picking people when you share a doc or assign a ticket. Behind it there's an endpoint like GET /users?q=ali that returns names and emails as you type.
That endpoint tends to get written quickly and reviewed last. Often the only check is whether the caller is logged in. So any signed-in user can type one letter at a time and walk your whole user table, across every tenant, emails included.
A few checks that close it:
- Scope the query to the people the caller is allowed to see. In a multi-tenant app that means the caller's organization, and sometimes only members of the same workspace or project.
- Check the action too. If the picker is for sharing document 42, confirm the caller can share document 42 before returning anyone.
- Return only what the picker needs. A display name and an avatar are usually enough. Leave email out unless the caller already has a reason to see it.
- Set a minimum query length and a rate limit, so nobody can page through the list with
q=a,q=b,q=c.
Quick test: log in as a user in tenant A and search for a name you know exists only in tenant B. If it shows up, the picker is leaking.
Top comments (0)