API security assessment for Routewise
Testing of a public and partner API for authorisation flaws and data exposure. A case study by James O'Connor, Penetration Tester & Security Consultant.
Challenge
Routewise, a last-mile delivery startup, opened its API to partners and wanted assurance that one partner could never see another partner’s data.
Solution
I tested authentication, object-level authorisation, rate limiting and input handling across 140 endpoints and delivered fixes as code suggestions with regression tests.