1. Secure API Design intermediate

    A developer platform's API is used by thousands of external integrators. What security properties must be defaults rather than options?

    2 min answer postmanapi-securitydefaultsscopes
  2. Secure API Design advanced

    A marketplace API is used by sellers, buyers, internal services and third-party tools. Which security properties must be enforced at the API layer, and which must not be?

    2 min answer api-securityauthorizationrate-limitingenumeration
  3. Secure API Design advanced

    How would you make it structurally impossible for a developer to add an endpoint that returns another tenant's data?

    2 min answer multi-tenancyisolationauthorisationstructure
  4. Secure API Design advanced

    In March 2023 OpenAI disclosed that a bug in the redis-py async client let one request receive data left behind in a recycled connection, so some users saw other users' chat titles and some payment details. The authorisation code was not at fault. Which class of control was missing, and what would you change?

    3 min answer openaiconnection-poolmulti-tenancyrequest-scoped-identity
  5. Secure API Design advanced

    Review this design. Every one of 40 API endpoints checks that the caller owns the requested resource by fetching it and comparing an owner field in the controller. A penetration test found one endpoint missing the check. What would you change and what would you leave alone?

    3 min answer authorizationbolaidorapi security
  6. Secure API Design advanced

    You are reviewing a new public API before launch. What do you check, in priority order?

    2 min answer api-securityowaspreviewauthorization