Find the security bug in generated code
Medium30 minFree, no account
Idiomatic, readable, and it will leak every other customer's data.
The question
A model generated this endpoint from "let a user download their own invoice as a PDF".
Find every security problem and rank them by what you would fix before deploying.
app.get("/invoices/:id/pdf", requireAuth, async (req, res) => {
const { id } = req.params;
const invoice = await db.query(
`SELECT * FROM invoices WHERE id = '${id}'`
);
if (!invoice) return res.status(404).send("Not found");
const file = path.join(INVOICE_DIR, `${invoice.filename}`);
res.setHeader("Content-Type", "application/pdf");
res.send(fs.readFileSync(file));
});30:00Commit to an answer before you open the solution. Reading it first teaches you to recognise good answers, which is not the skill being tested.
Stuck?
0 of 3 hints takenThe worked solution
written by a person · not a gradeScore yourself
0 of 5 marked- Found the missing ownership check and ranked it first35
- Found the SQL injection and fixed it with parameters25
- Found the path traversal and resolved-then-verified20
- Put authorisation in the query rather than a later branch10
- Noticed the blocking read or the enumeration oracle10
We run no AI here and nothing on this page grades you. The score is yours, and the useful number is the one you get on the same problem a month from now, cold.
kept in this browser only