← Web Security Foundations
ReadingLesson 1 of 5 · 12 min

How a request gets authorised

Every lab that follows turns on one question: how does the server decide what this request is allowed to touch? A session identifies the caller; authorization decides what that caller may reach. When the second step trusts something the caller controls, the door is open.

Read the concept on broken access control, then open the first lab.

Sign in to track thisUnderstanding broken access control →