Part 0 · 2 chapters · ~12 min

Application Security I: OWASP API Security Top 10

The 2023 OWASP API Security Top 10 grouped into themes, broken object and property-level authorisation with code, mass assignment, authentication weaknesses, function-level checks, resource consumption and sensitive business flows, and API inventory.

1

The most common API flaw

code
// vulnerable: trusts the id
app.get('/v1/statements/:id', auth, async (req, res) => res.json(await db.statement.findUnique({ where: { id: req.params.id } })));

// fixed: scoped by the caller, 404 for anything not theirs
app.get('/v1/statements/:id', auth, async (req, res) => {
  const s = await db.statement.findFirst({ where: { id: req.params.id, ownerId: req.user.id } });
  if (!s) return res.status(404).json({ error: 'not_found' });
  res.json(toPublicStatement(s));                     // explicit output shape: no internal fields leak (API3)
});

// mass assignment (API3): never spread the body into an update
await db.user.update({ where: { id: req.user.id }, data: pick(req.body, ['displayName', 'avatarUrl']) });   // not { ...req.body } (role: 'admin')
BROKEN OBJECT LEVEL AUTHORISATION
API1:2023, the most common API flaw
attacker (user 17)GET /v1/statements/:iddatabaseGET /v1/statements/9001 (own: 200)GET /v1/statements/9002 (someone else)
swipe the figure sideways, or tap expand for full screen
1/4
authenticated is not authorised
The attacker is a real, logged-in user. Authentication passed; the bug is that the handler never checks the statement belongs to them.
a valid tokenthe wrong object
2

The ten, grouped

The list is OWASP's API Security Top 10 (2023 edition). Grouping them by theme makes them easier to remember and to turn into review checklist items (Merge Reviews course).

OWASP API SECURITY TOP 10 (2023), GROUPED
ten risks in six themes
object accessAPI1 object-level and API3property-level authorisation (massassignment, excess data).identityAPI2 broken authentication: weaktokens, no rate limits on login,OTP brute force.function accessAPI5 function-level authorisation:user calls an admin endpoint.resources and flowsAPI4 unrestricted resourceconsumption; API6 unrestrictedaccess to sensitive businessflows.outboundAPI7 SSRF; API10 unsafeconsumption of third-party APIs.hygieneAPI8 misconfiguration; API9improper inventory (forgotten v1,shadow endpoints).
swipe the figure sideways, or tap expand for full screen
1/6
object and property
Check ownership on every object and use explicit allow-lists for fields a client may read or write (no blind ORM updates from request bodies).
API1 and API3scope objects, allow-list fields