The Unauthenticated Customer Lookup — JavaScript Bug Hunt
Modelled on the Panera Bread exposure (2018): an ordering API endpoint returned customer names, addresses, birthdays and the last four card digits to anyone…
- Language: JavaScript
- Layer: Backend
- Difficulty: Easy
- Concepts: Security, Authentication
- Modelled on: Panera Bread · 2018
- Visible tests: a valid key returns the safe fields; no key means no data; sensitive fields never leave
- Reward: 50 XP for a complete fix
Briefing
Modelled on the Panera Bread exposure (2018): an ordering API endpoint returned customer names, addresses, birthdays and the last four card digits to anyone who called it — no authentication at all. It stayed open for about eight months after being reported.
lookup.js answers any query.
Fix lookupCustomer so it requires a valid API key and returns only non-sensitive fields.
Bug report
BUG-PANERA · Priority: Critical · Reported by: security disclosure
lookupCustomer(store, customerId, apiKey, validKeys) must return { status, customer }:
- "unauthorized" when apiKey is missing or not in validKeys
- "not-found" when the customer does not exist
- "ok" with ONLY { id, firstName, city } — never the full address, birthday or card digits
Observed: any caller gets the complete record.
Logs
[api] GET /customer/8812 apiKey=(none) -> full record incl. cardLast4
[api] endpoint open for 8 monthsThe code as shipped
src/orders/lookup.js (editable)
exports.lookupCustomer = function (store, customerId, apiKey, validKeys) {
var customer = store[customerId];
if (!customer) return { status: "not-found", customer: null };
return { status: "ok", customer: customer };
};
Read-only context: src/orders/MODEL.js.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.