APIs tend to expose endpoints that handle object identifiers, creating a wide attack surface Level Access Control issue. Broken Object-Level Authorization (BOLA) checks should be considered in every function that accesses a data source using input from the user.
This white paper examines: