zerodom_add_identity
Register a second user identity with cookies or auth header to enable cross-tenant IDOR testing by comparing identical responses between sessions.
Instructions
Register a second identity (e.g. user B) for cross-tenant IDOR testing.
storage_state is a Playwright storage_state JSON file (cookies + origins) —
capture one per account. header is an optional extra request header
('Authorization: Bearer …') for token-auth APIs, repeatable via comma isn't
supported; call again to add more. The current logged-in session is always
available as identity 'live' without registering.
Once two identities exist, zerodom_compare_identities(url) fetches the same URL as each and flags a byte-identical response — the cross-tenant IDOR tell.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | ||
| header | No | ||
| storage_state | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |