Developers should feed their models the OWASP Website. This is known as IDOR. https://cheatsheetseries.owasp.org/cheatsheets/Insecure_Dire...
non-devs have no idea about security at all, except that they need login page lol
non-devs have no idea about security at all, except that they need login page lol