OWASP Top API Security Risks – 2023
owasp.org
owasp.org
I do wonder how the rise of technologies such as GraphQL have impacted this over the years. It’s obviously a big problem with REST APIs as well but the way I would think about securing it is fairly well understood I think.
I don’t have the experience with GraphQL to know any better but from my brief exposure they seem like they might be particularly vulnerable to this kind of thing and I was hoping someone here might be able to tell me if that intuition is true or not.
This is certainly a protection that we’ve lost as we moved away from server rendered architecture, where no APIs are exposed and only explicitly needed data is sent to the client. Not passing judgment, but there is a higher risk profile in multiple ways for a SPA.
Especially when you have technologies like Firebase or something like that where you might be interacting with the database essentially from your front end code.
That can end up leaving a big gap between what you are visually exposing and what you’re actually exposing.