Simple Authorization via PHP Classes
-
Updated
Feb 13, 2017 - PHP
Simple Authorization via PHP Classes
Declarative validation for Go maps & HTTP JSON/multipart payloads — nested objects, lists, conditional rules, whitelist struct binding. No struct tags.
Walkthrough demonstrating real-world exploitation and mitigation of critical API security flaws (Mass Assignment to Logging & Monitoring).
Expected attribute values for Pundit strong parameters — declare allowed per-attribute scalar values in your policies, alongside expected_attributes.
Educational Express API security lab: response filtering, role-based authorization, owner checks, mass-assignment protection, OpenAPI, Postman, and automated tests.
DEMO for ASP.NET Worst Practices sessions
Static-analysis CLI (GitHub Action) that flags client-controlled tier/plan/role values reaching an entitlement decision without Stripe-webhook-verified gating.
A simple task list app, with completion mark, user input & form validation. Basic routing and controllers, Blade templating, database interactions with Eloquent ORM, CRUD operations, form validation, session handling
Spring boot application developed to learn how to use the framework and understand how vulnerabilities are manifested in the application and how to prevent them.
Mass-assignment probe — re-sends a captured create with extra fields and emits a PoC curl per stuck field.
VAPT Master Checklist for web application vulnerabilities, including detailed checklists and techniques for various attack vectors.
A local, entirely fictional teaching demo of Broken Object Property Level Authorization (OWASP API3:2023) — a secure expense-claim API beside an intentionally vulnerable contrast service.
To associate your repository with the mass-assignment topic, visit your repo's landing page and select "manage topics."