SCIM, directory sync, and invites
Provisioning bugs are authorization bugs on user creation. Compare two orgs you belong to. Do not create users in a tenant that is not yours.
Tags: scim, invite, provision
Level: intermediate
Method
List the routes you were given
Invite create, invite accept, SCIM Users, and directory sync. Stay on the routes the program includes. A discovered admin path is inventory until you are allowed to call it.
Tools: Burp Suite
Two orgs you belong to
Use a member in org A and a member in org B. Replay A's create or role change with B's token. The question is whether the org id is checked on the write.
Tools: Burp Suite
Role on the token you have
Call the same route as a member and as an admin, if the program gave you both. A member token that changes a role is the note. Do not guess an admin id.
Tools: Burp Suite
Invite token
Accept an invite you issued, in a browser other than the one that created it, and then a second time. Record whether it is bound to an email and whether it is single-use. The mailbox has to be yours.
Tools: browser
Directory sync drift
If a user is removed in the directory and still has a session in the app, record the delay you observed. Do not delete someone else's account to test it.
Tools: browser
Field notes
- SCIM and the invite form can authorize differently. Test the one you can reach.
- An invite URL token that is reusable belongs in the same note as the reset brief. Say which behavior you showed.
- Creating a user in a third org is out.