Skip to content

[๐Ÿซ In-Person] Access Control Vulnerabilities in GraphQL with Bogdan Tiron ๐Ÿ”ž

Photo of Kevin Smith
Hosted By
Kevin S.
[๐Ÿซ In-Person] Access Control Vulnerabilities in GraphQL with Bogdan Tiron ๐Ÿ”ž

Details

This event will be a single talk on Examining Access Control Vulnerabilities in GraphQL - A Feeld Case Study with Bogdan Tiron

โš ๏ธ This will be an in-person event, the venue is Sheffield Tech Parks.

Agenda:

  • ๐Ÿ• Pizza/Drinks (18:15 - 18:30)
  • ๐Ÿ—ฃ Introduction (18:30)
  • ๐Ÿ‘‰ Examining Access Control Vulnerabilities in GraphQL - A Feeld Case Study
    (18:35ish)
  • ๐Ÿป Social @ Pub (after the talk)

๐Ÿ‘‰ Examining Access Control Vulnerabilities in GraphQL ๐Ÿ”ž
This talk explores the importance of implementing robust access controls in GraphQL and REST APIs and the severe consequences when these controls are not properly enforced. GraphQL, a flexible data query language, allows clients to request exactly the data they need, but without proper access control mechanisms, sensitive data can be easily exposed. Using the Feeld dating app as a case study, we will dive into a critical security review of how the lack of access controls in GraphQL and REST endpoints led to the exposure of usersโ€™ personal data, including sensitive photos, videos and private messages. This session will highlight common access control vulnerabilities in GraphQL and REST implementations , real-world examples of security lapses, their impact and remediation.

๐Ÿ“‹ Code of Conduct
We want dotnetsheff to be a welcoming and respectful community for everyone. Please take a moment to read and follow our guidelines:

  • โœ… Weโ€™re committed to providing a harassment-free experience for all attendees.
  • โœ… Please be sensible with drinks โ€“ we want everyone to feel comfortable.
  • โœ… Remember, we host dotnetsheff in a shared co-working space. All food, drinks, and biscuits at the venue belong to Sheffield Tech Parks โ€“ please donโ€™t take anything that isnโ€™t provided for the meetup.
  • โœ… Letโ€™s work together to create a friendly, inclusive, and supportive environment.
Photo of dotnetsheff group
dotnetsheff
See more events
Sheffield Technology Parks
Arundel Street ยท Sheffield