Mass assignment
Mass assignment is a field the server binds and the UI never sends: role, tenant, price, or a verified flag. The test is one extra field on an object you own, and whether the stored record changes.
Skill: Access control and tenant boundaries
Ask: Can account A read or change an object that belongs to account B, including a job, export, or leftover endpoint?
Stop: One object you own is denied to the other account, and one object you should not own is not returned.
Practice the class in the browser: PortSwigger Web Security Academy. The lab is theirs. This page is the stop condition and the disclosures.
Checklists
None linked for this class yet.
Disclosures
No public card yet.
Gadgets
- Mass assignment / extra JSON field - role, isAdmin, verified, balance, price, tenantId, twoFactorEnabled in a request the client never sends.
Playbooks
- Mass Assignment & Hidden Fields - Send the fields the UI never sends. The schema is the attack surface.
Payloads
- Mass assignment - Extra keys on register / PATCH / GraphQL update. Prove the new field changes authz, not just the JSON echo.
Questions
The schema lists a field the form hides. Am I done?
The schema is the map. The finding is a stored change on your object. A field the server ignores is not the bug.
Is this the same as IDOR?
IDOR is another person's object id. Mass assignment is an extra property on a write you are allowed to make. Both are access control. Report the one you showed.
This page is the linked pack hunt_brief("assignment") returns on the MCP connector. Authorized testing only.