Sort API authorization smells
Classify common API access-control findings into the right OWASP API Security categories.
Sort each finding by the boundary that failed. BOLA: wrong object BOPLA: wrong property BFLA: wrong function Broken authentication Customer A changes /orders/44 to /orders/45 and reads Customer B's order. A normal user calls POST /admin/users/suspend directly and the action runs. The profile endpoint returns salaryBand and managerNotes to the employee. The API accepts a JWT with alg:none and treats it as signed. A tenant admin can update another tenant's team_id by changing the path parameter. A customer adds creditLimit:999999 to a PATCH body and the server saves it. A basic-plan user calls the enterprise-only export endpoint and gets a…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in