Your ERP’s ‘Follow’ Button Is a Data Leak Hiding in Plain Sight
ERPNext’s Document Follow feature was quietly leaking unauthorized data to users who had no business seeing it. The vulnerability wasn’t in complex business logic β it was in a ‘harmless’ convenience button that checked feature-level visibility but never enforced object-level authorization. If you run any Frappe-based system, your internal documents may have been exposed to the wrong people. Here’s why authorization, not authentication, is where real security lives β and why every convenience feature is a security question you haven’t answered yet.