Zone Transfer in Hanami
How Zone Transfer Manifests in Hanami
Zone Transfer in Hanami applications typically occurs when applications mishandle multi-tenant data isolation, allowing users to access resources belonging to other tenants. This security vulnerability, also known as BOLA (Broken Object Level Authorization), manifests in several Hanami-specific patterns.
The most common manifestation appears in Hanami's repository pattern. Consider a multi-tenant application where each tenant has its own data partition. A vulnerable implementation might look like: