Testing API Authorization
By Richard Augenti
Exploit broken object-level and function-level authorization in a running API, fix the checks, and add the automated tests that keep the fixes honest.
Free to browse. Takes about 60 minutes once you start.
Lab Overview
The accounts-api authenticates every request - no token, no access. What it never checks is whether the caller who authenticated is allowed to see the specific account they asked for.
That gap is Broken Object-Level Authorization, the first item on the OWASP API Security Top 10. In this lab you take the attacker's seat first: change an object ID in an otherwise valid request and read another user's account. Then you add the ownership check that closes it, and write the authorization test that would have caught it in review.
The API is pure Python standard library and runs entirely on your own lab machine. No cloud account is involved and nothing you do here reaches real infrastructure.
What to Expect
- Environment: a single Ubuntu machine you connect to over SSH, with the accounts-api and everything it needs already installed under ~/lab. No cluster required.
- Access: SSH credentials are generated for your session and shown in the workspace. They are destroyed when the lab ends.
- Checking your work: verify.sh machine-checks each objective, and setup.sh --force rebuilds the lab from scratch if you want to start over.
- Progress: your work is not saved. If the lab expires or you quit, the machine and everything on it is destroyed.
What are hands-on labs?
A lab is a real environment, not a simulation. You get a live machine with the tooling already installed, a task taken from production work, and root access to take it apart. Nothing is mocked, nothing is multiple choice. It either works or it doesn't.
Real tooling
The same commands you would run at work, on a machine that is already set up for them. No screenshots, no sandboxed toy version.
Break it freely
Everything is disposable. When the clock runs out the environment is destroyed with everything in it, so there is no reason to be careful.
Useful on Monday
Built by engineers who run these systems in production. Skills you can apply to your own stack the same week, not exam preparation.