Authentication Is Not Authorization
Authentication asks who you are. Authorization asks what you may do.
The Django course made this point once. It is worth a whole course because the second question is where nearly every student project is broken, and the break is invisible: everything works perfectly when you test it as yourself.
The failure, precisely. A view is protected by a login requirement, so a signed-out visitor is redirected. Correct. But any signed-in person can then act on anyone's data by changing the number in the URL, because nothing checks ownership.
It takes about four seconds to exploit and it is the single most common real vulnerability in portfolio projects. It survives because the developer only ever tested it while signed in as the owner.
✦ The habit that prevents it
Test as an attacker, not as the author. Sign in as a second account and try to read, edit and delete the first account's data by typing URLs. Do that once per feature and this entire class of bug disappears from your work.
Mark this lesson complete
Signed in, your progress follows you to every device.