Access Control: Code Review

🔒 Pro Medium Code review Online Avg. time 30 min Solved by 0 2 keys · 50 pts Code Review

Injection bugs are a dangerous line you can point at. Broken access control is the opposite: a line that should be there and isn't. Reviewing for it means reading each sensitive action and asking whether it verifies that this user may do this, to this object. This exercise teaches that habit.

Skills covered: Code ReviewAccess control
Log in or create a free account to submit keys and track your progress.

What you will learn

  • Explain why broken access control is an absence, not a dangerous call
  • Review an endpoint for a missing ownership or role check
  • Spot where 'logged in' is confused with 'allowed'
  • Know why access checks belong in one enforced place, not scattered

Before you start

These exercises cover what this one builds on.

In this exercise

  1. The bug that isn't on the page
  2. "Logged in" is not "allowed"
  3. Where to look, and what to look for
  4. Why scattered checks fail
🔒

This is a Pro exercise

Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.

See Pro plans Create a free account

4 sections · 2 keys · 50 points