Problem
API security review model that inventories endpoints and checks each for object-level authorisation on client-supplied ids, function-level authorisation on privileged routes, mass assignment, unauthenticated writes, and unbounded authentication paths.