Vulnerability field guide
Access Control
A 403 Forbidden only proves that one spelling of a request was refused. Here is how trailing slashes, path parameters, rewrite headers like X-Original-URL, spoofed client IPs and alternate methods walk past gates enforced at a proxy or router, and why the decision has to live in the application.
1 article 8 min total Overview to advanced techniques