Broken Object Level Authorization

Use when testing whether an API lets one user access another user's objects by changing an ID — the BOLA/IDOR flaw that tops the OWASP API list, plus the server-side fix.

jihedbfr-art Updated

File contents

jihedbfr-art/cyber-skills/tree/main/skills/04-api-security/01-broken-object-level-authorization commit 3ffc82c62e

Frequently asked questions

npx skillmds@latest add jihedbfr-art/broken-object-level-authorization