API authorisation
APIs regularly prove who is calling and then never check whether that caller should have the thing they asked for.
Authentication is visible and gets implemented once at the edge. Authorisation has to happen per object, per request, and is easy to forget on the fourth endpoint somebody adds. It is the most common serious API flaw by a distance, and it is invisible to anybody testing with a single account.
Checked against the primary source.
