Object and function permissions are checked inconsistently or too broadly.
Use this profile to understand the building block briefly, place it in the model, and open related building blocks.
Theoretical construct: explains a term, principle, or mental model.
Concrete cog in the system that works inside larger relationships.
Broken authorization occurs when a system lets an authenticated user perform actions on objects beyond that identity's permissions.
The widespread use of APIs made access control on individual data objects a distinct security problem. OWASP consequently placed Broken Object Level Authorization first in its API Security Top 10 as API1:2023.
Authentication says who is making a request; authorization decides what that identity may do for each function and object. The check must happen server-side on the concrete object, even when its ID comes from the request.
The system associates a request with an authenticated identity.
A policy describes allowed actions and conditions.
Access to each concrete object is checked separately.
Correct authorization prevents data access and actions outside the intended user context.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.