IDOR is not dead, it just moved to the second request
Every team I test has learned to check ownership on GET /orders/:id. Almost none of them check it on the thing the order links to.
The pattern I keep finding:
GET /orders/1042— correctly refuses. Good.GET /orders/1042/invoice— checks that the invoice exists and that you are authenticated. Does not re-check that the order is yours.
The second endpoint was written by someone who assumed you could only reach it from the first. That assumption is the bug, and it is almost never written down anywhere a reviewer would see it.
httpGET /api/v2/orders/1042/invoice HTTP/1.1 Authorization: Bearer <your own perfectly valid token>
Worth walking every nested route on any object you can legitimately reach. The parent is guarded; the children usually are not.