I don't understand why people are saying this is a security issue.
If user a has private document 1234 at /doc/1234 and user b has private document 1235 at /doc/1235
when user a goes to /dec/1235 IT SHOULD NOT RETURN THAT DOCUMENT.
Who in their right minds considers obscurity to be a replacement for authorization?
If a random anonymous individual can access private data by hitting a url, the problem is not the id used in the url.