Endpoint Map

Browse as Alice (Actor A). Set Bob as Actor B in ACAS.

MethodEndpointTypeExpected ACAS Result
GET/api/users/meprotectedNot flagged
GET/api/users/{id}/profileIDORCONFIRMED ~85
PUT/api/users/{id}/profileIDORCONFIRMED ~80
GET/api/users/{id}/ordersIDORCONFIRMED ~80
GET/api/orders/{id}IDORCONFIRMED ~78
GET/api/documents/{id}IDORCONFIRMED ~88
DELETE/api/documents/{id}IDORCONFIRMED ~82
GET/api/users/{id}/payment-methodIDORCONFIRMED ~92 HIGH
GET/api/users/{id}/apikeyIDORCONFIRMED ~95 CRITICAL
GET/api/export?user_id={id}IDORReview Queue
POST/api/reports/generateIDORReview Queue
GET/api/users/{id}/messagesprotectedNOT flagged 403
GET/api/productspublicFALSE POSITIVE
GET/api/products/{id}publicFALSE POSITIVE