auth-sec
yaklang/hack-skills
This guide serves as the core entry point for comprehensive security testing of identity and access control mechanisms. It is designed to help testers systematically identify vulnerabilities across login flows, session management, object authorization (IDOR), and modern protocols like JWT, OAuth, CORS, and SAML. Use this when planning security audits for any web application with user accounts.