The Unauthenticated Customer Lookup — JavaScript Bug Hunt

Modelled on the Panera Bread exposure (2018): an ordering API endpoint returned customer names, addresses, birthdays and the last four card digits to anyone…

  • Language: JavaScript
  • Layer: Backend
  • Difficulty: Easy
  • Concepts: Security, Authentication
  • Modelled on: Panera Bread · 2018
  • Visible tests: a valid key returns the safe fields; no key means no data; sensitive fields never leave
  • Reward: 50 XP for a complete fix

Briefing

Modelled on the Panera Bread exposure (2018): an ordering API endpoint returned customer names, addresses, birthdays and the last four card digits to anyone who called it — no authentication at all. It stayed open for about eight months after being reported.

lookup.js answers any query.

Fix lookupCustomer so it requires a valid API key and returns only non-sensitive fields.

Bug report

BUG-PANERA · Priority: Critical · Reported by: security disclosure

lookupCustomer(store, customerId, apiKey, validKeys) must return { status, customer }:

  • "unauthorized" when apiKey is missing or not in validKeys
  • "not-found" when the customer does not exist
  • "ok" with ONLY { id, firstName, city } — never the full address, birthday or card digits

Observed: any caller gets the complete record.

Logs

[api] GET /customer/8812 apiKey=(none) -> full record incl. cardLast4
[api] endpoint open for 8 months

The code as shipped

src/orders/lookup.js (editable)

exports.lookupCustomer = function (store, customerId, apiKey, validKeys) {
  var customer = store[customerId];
  if (!customer) return { status: "not-found", customer: null };
  return { status: "ok", customer: customer };
};

Read-only context: src/orders/MODEL.js.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.