Simple Authorization via PHP Classes
-
Updated
Feb 13, 2017 - PHP
Simple Authorization via PHP Classes
Declarative validation for Go maps & HTTP JSON/multipart payloads — nested objects, lists, conditional rules, whitelist struct binding. No struct tags.
Educational Express API security lab: response filtering, role-based authorization, owner checks, mass-assignment protection, OpenAPI, Postman, and automated tests.
Walkthrough demonstrating real-world exploitation and mitigation of critical API security flaws (Mass Assignment to Logging & Monitoring).
Expected attribute values for Pundit strong parameters — declare allowed per-attribute scalar values in your policies, alongside expected_attributes.
A simple task list app, with completion mark, user input & form validation. Basic routing and controllers, Blade templating, database interactions with Eloquent ORM, CRUD operations, form validation, session handling
DEMO for ASP.NET Worst Practices sessions
Static-analysis CLI (GitHub Action) that flags client-controlled tier/plan/role values reaching an entitlement decision without Stripe-webhook-verified gating.
Spring boot application developed to learn how to use the framework and understand how vulnerabilities are manifested in the application and how to prevent them.
Mass-assignment probe — re-sends a captured create with extra fields and emits a PoC curl per stuck field.
VAPT Master Checklist for web application vulnerabilities, including detailed checklists and techniques for various attack vectors.
A local, entirely fictional teaching demo of Broken Object Property Level Authorization (OWASP API3:2023) — a secure expense-claim API beside an intentionally vulnerable contrast service.
To associate your repository with the mass-assignment topic, visit your repo's landing page and select "manage topics."