Access Control: Code Review
Injection bugs are a dangerous line you can point at. Broken access control is the opposite: a line that should be there and isn't. Reviewing for it means reading each sensitive action and asking whether it verifies that this user may do this, to this object. This exercise teaches that habit.
Log in or create a free account to submit keys and track your progress.
What you will learn
- Explain why broken access control is an absence, not a dangerous call
- Review an endpoint for a missing ownership or role check
- Spot where 'logged in' is confused with 'allowed'
- Know why access checks belong in one enforced place, not scattered
Before you start
These exercises cover what this one builds on.
- Broken Access Control Medium
- SQL Injection: Code Review Medium
In this exercise
- The bug that isn't on the page
- "Logged in" is not "allowed"
- Where to look, and what to look for
- Why scattered checks fail
🔒
This is a Pro exercise
Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.
See Pro plans Create a free account4 sections · 2 keys · 50 points