Auth bypass on API token refresh
How a critical authentication bypass in *.northwind.com was found, reported to Northwind Cloud and fixed.
Summary
A critical issue in *.northwind.com, reported to Northwind Cloud and now fixed. This is the story of finding it, what it would have cost, and what changed.
Finding it
The interesting part was not the bug itself but the assumption behind it: that a value checked once stays checked. It does not.
httpPOST /api/v2/refresh HTTP/1.1 Host: northwind.com Content-Type: application/json {"token":"<redacted>"}
Impact
An attacker could exploit this against Northwind Cloud production traffic without prior access.
What changed
Northwind Cloud shipped a fix and confirmed it on retest. Worth reading their scope before you start — it is unusually specific about what counts.