The recently published “OWASP API security top 10” report analyzes the anti-patterns that lead to vulnerabilities and security risks in APIs. In this 10 part series, we introduce these API anti-patterns. Every API professional should know about these anti-patterns.

Broken Object-Level Authorization from the OWASP API security paper

API security anti-pattern: Broken Object-Level Authorization
APIs tend to expose endpoints that handle object identifiers, creating a wide attack surface Level Access Control issue.

Object-level authorization checks should be considered in every function that accesses a data source using input from the user.

