TIDAL CMS session-token handoff — proof of concept (F-001 / SER-168)

This page is hosted on — a domain the tester controls, whose full origin string starts with https://cmsapi.tidal.com (it just doesn't stop there). cmsapi.tidal.com's token-handoff route tests the askingOrigin parameter with String.prototype.startsWith() instead of an exact match, so this origin is wrongly treated as trusted.

To reproduce: in the same browser, sign in to https://cmsapi.tidal.com as a CMS user first. Then click the button below.

Status:

waiting for click…

Temporary PoC page for an authorized security assessment of tidal.com (finding F-001 / Linear SER-168). Hosted on er3bus infrastructure for reproduction purposes only — not affiliated with TIDAL or Block. Remove after use.