Practical API Authorization Testing
A structured approach to testing object and function authorization in APIs.
Practical API Authorization Testing
Authorization testing asks whether the server correctly enforces who can access an object or perform an action.
Object-Level Authorization
Create a test matrix covering multiple authenticated identities and object identifiers.
Function-Level Authorization
Test whether privileged endpoints enforce the expected server-side role checks.
HTTP/1.1 403 Forbidden
Content-Type: application/json
Mitigation
Authorization decisions should be enforced server-side for every sensitive operation. Client-side hiding is not authorization.
Conclusion
A good authorization test is systematic, identity-aware and focused on server-side decisions.
Related Research
HTTP Toolkit to Solve the Simcard required application proxy
A simple technique to intercept Android application traffic when the app works only over mobile data and ignores traditional proxy settings.
Understanding HTTP Request Smuggling
A methodology for analyzing parser inconsistencies between HTTP components.
Getting Started With Frida
An introduction to runtime instrumentation for authorized application research.