Web Security · module
Access control
Access control decides who can do what. When it breaks, users can read or change data that isn't theirs. It's the number one risk in the OWASP Top 10.
Start module- Lesson 1beginner
What is access control?
- Explain the difference between authentication, session management and access control
- Recognise vertical, horizontal and context-dependent access control
- Understand why broken access control is so common
10 min
- Lesson 2practitioner
Insecure direct object references (IDOR)
- Identify where an application exposes object identifiers
- Test for horizontal access control flaws safely
- Understand why unpredictable IDs are not a fix
15 min
- Lesson 3practitioner
Preventing access control vulnerabilities
- Apply deny-by-default and centralised authorisation
- Choose between role-based and attribute-based access control
- Build tests that stop access control regressions
12 min