OWASP A01 access control: authentication does not authorize every object

Check API authorization by object, tenant and action rather than relying on hidden buttons.

Contents of this article

Identity and permission are separate

OWASP A01:2025 covers broken access control. After authentication, the server must still authorize each action on each object. URL identifiers and hidden buttons do not enforce ownership or permissions.

Enforce tenant boundaries

Derive tenant context from a trusted session rather than trusting a submitted identifier. Apply the boundary to queries, exports, downloads and background jobs. Review cached decisions and issued links after permissions change.

Test a permission matrix

Test anonymous, ordinary, cross-tenant and administrative identities against reads, writes, deletes and bulk operations. Expected denials must occur server-side and be traceable. Successful access by the intended user is only one test case.

Align caching with authorization

Prevent shared caching from exposing private responses and validate cache keys and invalidation. A WAF generally does not know business object ownership. Keep authorization and its audit trail in the application.

References

OWASP Top 10 2025: Broken Access Control

Continue reading

Read related content

Back to industry insights Contact technical support