← Web Security Foundations
ReadingLesson 1 of 5 · 12 min
How a request gets authorised
Every lab that follows turns on one question: how does the server decide what this request is allowed to touch? A session identifies the caller; authorization decides what that caller may reach. When the second step trusts something the caller controls, the door is open.
Read the concept on broken access control, then open the first lab.