OWASP API Top 10 coverage
BOLA, Broken Authentication, Object Property Level Authorisation, Unrestricted Resource Consumption, Function Level Authorisation, Server-side Request Forgery, Security Misconfiguration, Lack of Protection from Automated Threats, Improper Inventory Management, Unsafe Consumption of APIs.
BOLA/IDOR testing protocol
Two test accounts minimum. Systematic substitution of every resource ID across every endpoint. Vertical and horizontal privilege escalation. Resource enumeration via sequential IDs.
JWT security tests
Algorithm confusion (RSA to HMAC), none algorithm, key injection, claim tampering, token replay, signature bypass, expiry bypass.
OAuth/OIDC testing
Open redirect for token theft, PKCE bypass, state parameter CSRF, token leakage in referrer/logs, scope escalation, implicit flow vulnerabilities.
GraphQL-specific tests
Introspection enabled, depth limiting absent, query complexity unlimited, batching abuse, aliases for rate limit bypass, field suggestions as enumeration.
Mass assignment testing
Add every privileged-sounding field (is_admin, role, balance, credit_limit, verified) to every POST/PATCH request body. Document which fields are accepted.