Simple Authorization via PHP Classes
-
Updated
Feb 13, 2017 - PHP
Simple Authorization via PHP Classes
Declarative validation for Go maps & HTTP JSON/multipart payloads — nested objects, lists, conditional rules, whitelist struct binding. No struct tags.
Educational Express API security lab: response filtering, role-based authorization, owner checks, mass-assignment protection, OpenAPI, Postman, and automated tests.
Walkthrough demonstrating real-world exploitation and mitigation of critical API security flaws (Mass Assignment to Logging & Monitoring).
Expected attribute values for Pundit strong parameters — declare allowed per-attribute scalar values in your policies, alongside expected_attributes.
A local, entirely fictional teaching demo of Broken Object Property Level Authorization (OWASP API3:2023) — a secure expense-claim API beside an intentionally vulnerable contrast service.
A simple task list app, with completion mark, user input & form validation. Basic routing and controllers, Blade templating, database interactions with Eloquent ORM, CRUD operations, form validation, session handling
DEMO for ASP.NET Worst Practices sessions
Static-analysis CLI (GitHub Action) that flags client-controlled tier/plan/role values reaching an entitlement decision without Stripe-webhook-verified gating.
Mass-assignment probe — re-sends a captured create with extra fields and emits a PoC curl per stuck field.
VAPT Master Checklist for web application vulnerabilities, including detailed checklists and techniques for various attack vectors.
Spring boot application developed to learn how to use the framework and understand how vulnerabilities are manifested in the application and how to prevent them.
To associate your repository with the mass-assignment topic, visit your repo's landing page and select "manage topics."