Operations · Security · Food halls

Cancelling an order you did not place

A purchase order is a promise to a supplier. We found nine ways one trader in a hall could reach another trader’s orders — cancel one, mark it received, or quietly move it onto their own books.


Most people think of a purchase order as a form. It is not. It is a promise to a supplier, and once it is sent it is the document two businesses will argue from if the delivery is short. Everything downstream hangs off it: the goods received note, the invoice, the stock that lands on your shelf, the cost that lands in your margin.

Which is why it matters who can touch one.

What we found in our own product

We went looking at the routes that act on a single purchase order by its number. Three of them checked whose order it was. Nine did not.

Driven properly — a real request, from an account granted exactly one kitchen in one hall, against an order belonging to a different business in a different hall — every one of the nine succeeded:

Their order could be cancelled. The whole document could be read, including the supplier, the reference and the unit costs they buy at. A draft could be deleted outright. It could be marked sent, which composes the supplier email. It could be marked received, which writes stock movements and raises the invoice behind money owed. The goods received note and the invoice lines — what the supplier is owed, per line — could be rewritten.

And the worst one: the order could be moved. An edit that changed which venue it belonged to, under a new reference, took the document out of its owner's list and put it in somebody else's.

Why it was invisible

The system did have a check on this family of documents, and it worked. It checked the company. Every purchase order has a company behind it, and a request from another company was refused properly.

But a food hall is not one company per kitchen. Several traders in one hall can sit under no company at all, or under the same one, and be entirely separate businesses with separate suppliers and separate margins. The check that was there had nothing to say about that, because a purchase order also belongs to a venue, and nothing was reading that.

So anyone reviewing it saw a guarded document family and moved on. That is the part worth taking away: a protection that covers one dimension of ownership reads, from a distance, exactly like a protection that covers all of them.

Questions worth asking about your own setup

If you share a system with other traders, these are fair things to ask the people who run it.

Who can see my purchase orders? Not who is supposed to — who can. The answer should name a mechanism, not a screen. "It is not in the menu for them" is not an answer; addresses can be typed.

Can anyone mark my delivery as received? Receiving is not paperwork. It moves stock and it usually creates a bill.

If somebody edits my order, is there a record? An audit line turns an argument into a fact.

Are my unit costs visible to the stall next door? What you pay your supplier is commercially yours, and a purchase order has it on every line.

How we fixed it, and how we know

One rule, in one place, used by all twelve routes across both files — rather than a check written twelve times, which is a check the thirteenth route forgets. A purchase order that is not yours now reads as one that does not exist, so the numbers cannot be walked through one at a time.

Then we removed the rule again and ran the attacks, to be sure the tests complained rather than passing quietly. Nine failed by name; the five controls — the manager acting on their own order, the owner acting on either — kept working. A fence that refuses everybody would pass every attack and break the screen, so those controls are half the test.


Try it on tonight’s service.

Nothing to install, no card. Not better by the weekend? Close the tab.