In managing entities in Parse there are a lot of objects that I need to tie to the current logged in user.

My concerns are:

  1. There is no backend code ensuring that the User being passed in is the current logged in user.
  2. Users could assign any newly created objects to other users.

They have this example TODO app which in the documentation shows no Cloud Code in place to ensure that the User that the Todo is assigned to is the currently logged in user.

Now that I look through the code I'm starting to think that whenever an object is saved it gets tied to the user. Can anyone explain why this application works and how it is associating the Todos with the User?

UPDATE: Nevermind, I found the place in their code where they specify the user to save for the Todo. My question is, what's stopping a user from writing code that saves the todo with someone else's user id?

this.todos.create({
        content: this.input.val(),
        order:   this.todos.nextOrder(),
        done:    false,
        user:    Parse.User.current(),
        ACL:     new Parse.ACL(Parse.User.current())
      });

UPDATE #2: If the User object has an ACL set to only allows users to be able to read User objects they own, then they wouldn't be able to query to get another user object to pass up. However, there are two other possible problems:

  1. Is it possible for them to pass the objectId of the user instead of the entire User object even if the user field on the Todos table requires
Edit
Report