The Endpoint That Forgot Private Meant Private — JavaScript Bug Hunt

Modelled on the Peloton API exposure (2021): an endpoint returned full profile data — age, weight, workout history — for any user id, ignoring the account's…

  • Language: JavaScript
  • Layer: Backend
  • Difficulty: Medium
  • Concepts: Security, Privacy
  • Modelled on: Peloton · 2021
  • Visible tests: the owner sees everything; a stranger sees only public fields of a private profile; a public profile is fully visible
  • Reward: 50 XP for a complete fix

Briefing

Modelled on the Peloton API exposure (2021): an endpoint returned full profile data — age, weight, workout history — for any user id, ignoring the account's "private profile" setting entirely. It was reachable without authentication.

profiles.js returns everything it has.

Fix getProfile so private accounts expose only their public fields to strangers.

Bug report

BUG-PELOTON · Priority: High (privacy) · Reported by: security

getProfile(store, userId, viewerId) must return the profile fields the viewer is entitled to:

  • the owner (viewerId equals userId) always sees every field
  • a stranger viewing a PUBLIC profile sees every field
  • a stranger viewing a PRIVATE profile sees only { id, displayName }
  • a missing user returns null

Observed: private profiles return their full record to any caller.

Logs

[api] GET /profile/8812 viewer=anonymous private=true -> full record
[api] age, weight and workout history returned for private accounts

The code as shipped

src/social/profiles.js (editable)

// Returns a user's profile as visible to the viewer.
exports.getProfile = function (store, userId, viewerId) {
  var user = store[userId];
  if (!user) return null;
  return user;
};

Read-only context: src/social/MODEL.js.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.