Intermediate · Application security API Security Design APIs with explicit authorisation, validation and safe limits.
6 lessons 2 guided labs 113 minutes estimated
What you will learn Create fictional employee and approver roles. List the request fields each role may submit. Identify why an employee-supplied approved flag is unsafe.
01 / Foundations Core principles and worked example 18 min 02 / Guided practice & assessment Review an expense API contract 30 min Build an API abuse test matrix 35 min Field notes and verification checklist 12 min Practise only in local, intentionally vulnerable or explicitly authorised environments. This course does not grant permission to test third-party systems.