Capstone: harden a vulnerable API
P57.secure-api-design.02 · Audience: guest, it-ml, language-pro · Prerequisites: Injection & the untrusted-input lens, Access-control bugs & the OWASP lens, Designing a secure API
Attackers do not probe one vulnerability class at a time, and fixing one hole while re-opening another is how hardening fails in practice — so the Security discipline's flagship capstone makes you fix everything at once. You are handed a small handler set seeded with the P57 vulnerability classes — an IDOR read, a mass-assignment update, and a concatenated search query — and asked to harden all of them together. The hidden suite is the abuse suite: an unauthorised document read, a privilege-escalating payload, and an injection term, and every one must fail. It also checks that legitimate requests still succeed, because over-blocking fails the capstone too — security that breaks the product isn't security.
Ask the mentor about this module
Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.
Keeping your files on this device
Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.
Capstone — fix every class, break nothing
Loading exercise…
My notes on this module
Loading your notes...