Part 0 · 2 chapters · ~12 min
Application Security I: OWASP API Security Top 10
The 2023 OWASP API Security Top 10 grouped into themes, broken object and property-level authorisation with code, mass assignment, authentication weaknesses, function-level checks, resource consumption and sensitive business flows, and API inventory.
1
The most common API flaw
code
// vulnerable: trusts the id
app.get('/v1/statements/:id', auth, async (req, res) => res.json(await db.statement.findUnique({ where: { id: req.params.id } })));
// fixed: scoped by the caller, 404 for anything not theirs
app.get('/v1/statements/:id', auth, async (req, res) => {
const s = await db.statement.findFirst({ where: { id: req.params.id, ownerId: req.user.id } });
if (!s) return res.status(404).json({ error: 'not_found' });
res.json(toPublicStatement(s)); // explicit output shape: no internal fields leak (API3)
});
// mass assignment (API3): never spread the body into an update
await db.user.update({ where: { id: req.user.id }, data: pick(req.body, ['displayName', 'avatarUrl']) }); // not { ...req.body } (role: 'admin')BROKEN OBJECT LEVEL AUTHORISATION
API1:2023, the most common API flaw
swipe the figure sideways, or tap expand for full screen
1/4
authenticated is not authorised
The attacker is a real, logged-in user. Authentication passed; the bug is that the handler never checks the statement belongs to them.
a valid tokenthe wrong object
2
The ten, grouped
The list is OWASP's API Security Top 10 (2023 edition). Grouping them by theme makes them easier to remember and to turn into review checklist items (Merge Reviews course).
OWASP API SECURITY TOP 10 (2023), GROUPED
ten risks in six themes
swipe the figure sideways, or tap expand for full screen
1/6
object and property
Check ownership on every object and use explicit allow-lists for fields a client may read or write (no blind ORM updates from request bodies).
API1 and API3scope objects, allow-list fields