API Expert
Aug 10, 2023

--

This is a horrible idea for multiple reasons.

First, the API application can do internal redirects (aka FORWARDS). Its part of the HTTP standard. This means that it can bypass ALL SECURITY IN THE GATEWAY! (https://medium.com/@apiexpert/why-api-gateways-are-dead-7c9e324ff70a )

Second, if the API application does any kind of ROLE checks (RBAC/ABAC), this will cause privilege escalation in the cache at the gateway (https://medium.com/@apiexpert/api-gateways-not-securing-caches-ff042a399452)

--

--

API Expert
API Expert

Written by API Expert

Owen Rubel is the 'API Expert'. He is an Original Amazon team member, Creator of API Chaining(R), Leader in API Automation

No responses yet