Public API data exposure
HighHigh impact · 13 pts
1 issue to fix before launch — see findings below
/api/profiles returned JSON containing personal or business fields without authentication. If this isn't meant to be public, require a login first.
Evidence
- status
- 200
- sensitive fields
- email, name, user_id
Why it matters
Public API routes that return user, customer, or admin data without a login let anyone read information meant to be private.
Recommendation
Require authentication and authorization before returning this data, and confirm anonymous requests receive 401 or 403.
Where to fix it
Add an authentication and authorization check inside the API route handler (Next.js route handler or server action) before it returns any data.
Paste this into Claude Code, Cursor, or your AI coding tool
Review this public API route. Confirm whether it should be accessible without authentication. If it returns user, customer, case, payment, or admin data, require authentication and authorization before returning the response. Add tests that unauthenticated requests receive 401 or 403.