OWASP A01 access control: authentication does not authorize every object
Check API authorization by object, tenant and action rather than relying on hidden buttons.
Contents of this article
Identity and permission are separate
OWASP A01:2025 covers broken access control. After authentication, the server must still authorize each action on each object. URL identifiers and hidden buttons do not enforce ownership or permissions.
Enforce tenant boundaries
Derive tenant context from a trusted session rather than trusting a submitted identifier. Apply the boundary to queries, exports, downloads and background jobs. Review cached decisions and issued links after permissions change.
Test a permission matrix
Test anonymous, ordinary, cross-tenant and administrative identities against reads, writes, deletes and bulk operations. Expected denials must occur server-side and be traceable. Successful access by the intended user is only one test case.
Align caching with authorization
Prevent shared caching from exposing private responses and validate cache keys and invalidation. A WAF generally does not know business object ownership. Keep authorization and its audit trail in the application.
References
OWASP Top 10 2025: Broken Access Control
