otherwise.sh

02 / Approach

The interesting part
is the second request.

One account retrieves a document. So far, everything looks ordinary. Repeat the request as someone else, and you have a more useful question: does the system check who owns it?

Same document. Different account.

Illustrative model

The request

GET /documents/field-notes

Document owner
account / 01
First request
account / 01
Second request
account / 02
What does the handler check?

The comparison

The document's owner

200 OK

A different account

200 OK

Ownership boundary crossed

The second account receives the same document. Signing in was enough; ownership was never checked.

Read the check
function mayRead(account, document) {
  return account.signedIn;
}

This example runs entirely in your browser. It uses fictional accounts and sends no requests to another system.

03What the example establishes

A successful response becomes useful evidence when it is tied to the condition that should have prevented it. The comparison makes that condition visible.

Real investigations have more moving parts. The principle carries across: vary an assumption, repeat the observation, and make the reasoning inspectable. That's the work we're trying to automate.

Have a system or a research question you'd like us to look at?

[email protected]

A few shortcuts

Home
Alt H
Research
Alt R
Approach
Alt A
Change appearance
Alt L
Close this window
Esc