P57 · Application & API Security

vulnerability classes, secure API design, secrets, supply-chain

Finding and fixing the vulnerability classes that break real applications — injection, path traversal, IDOR and mass assignment — plus secure API design, secrets hygiene and supply-chain safety.

Most vulnerabilities are not exotic. They are ordinary functions written by competent people who trusted one value they should not have trusted: an id from a URL, a filename from a form, a field name in a JSON body, a string concatenated into a query. This pillar is the hands-on half of the discipline — you are given the broken function, the exploit that proves it is broken, and the job of repairing it so that a test keeps it repaired.

The organising idea is that these bugs are two ideas wearing many costumes. The first is untrusted input treated as instruction: SQL injection and path traversal are the same failure at different boundaries, and both are fixed by parameterising or resolving rather than by filtering harder. The second is broken access control: IDOR and mass assignment are both the caller choosing what they get to touch, and both are fixed by deciding server-side what this identity may reach. The OWASP Top 10 arrives as a map for orienting yourself, not a list to memorise. From there the pillar zooms out to design — where authentication and authorization belong in a request's lifecycle, what must be settled at the boundary before any handler runs, and how to write errors that help a legitimate user without telling an attacker which accounts exist — and its flagship capstone hands you a working but vulnerable API to harden. It finishes at the build, because code is not the only thing you ship: keeping secrets out of the repository by scanning before they land, and keeping dependencies pinned, inventoried and patched.

Untrusted inputinjection and traversal katasAccess controlIDOR, mass assignmentAPI designboundaries, safe error hygieneBuildsecrets and supply chain
Two root causes in many costumes, repaired function by function, then designed out and kept out of the build.
P57 · Application & API Security — TransformerLab