Based on the exhibit, what is the BEST fix for the vulnerability being exploited?
A user with a standard account can retrieve documents by changing the `docId` value in the request. The application returns another employee's file without any authorization error.