OWASP/SecureCodingDojo

Second Degree Black Belt : Broken Authentication & Broken Access Control - View the chat messages

Closed this issue · 0 comments

Hi,

I am viewing the chat messages after signing a new jwt with an empty permissions, yet the challenge never ends.
I try to impersonate the other users (w/ 'currentuser' permissions) but I am logged out.
I get the /messages.json and according to the requirements this should be it . . . but it's not?
Can you please suggest how to complete? a solution?

"Second Degree Black Belt : Broken Authentication & Broken Access Control"