Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.8 KiB

API Reference: Testing API for Mass Assignment Vulnerability

Privilege Field Categories

Category Example Fields Impact
Role elevation role, userRole, account_type Admin access
Admin flags isAdmin, is_superuser Full privileges
Permissions permissions, scopes, groups Arbitrary access
Account status verified, is_active Bypass verification
Financial balance, credit, discount, price Monetary fraud
Ownership user_id, owner_id Data theft
Internal debug, is_featured Hidden features

Framework-Specific Payloads

Framework Payload Pattern
Rails/ActiveRecord {"user": {"role": "admin"}}
Django REST {"is_staff": true, "is_superuser": true}
Express/Mongoose {"$set": {"role": "admin"}}
Spring Boot {"authorities": [{"authority": "ROLE_ADMIN"}]}

OWASP API3:2023 Mitigations

Mitigation Description
DTO/Input Schema Explicit allowed fields per endpoint
Strong parameters Framework allowlist (Rails)
Serializer fields Django REST serializer definition
Property filter Drop unknown fields before binding

Test Tools

Tool Purpose
Burp Repeater Manual parameter injection
Param Miner (Burp) Hidden parameter discovery
Arjun Automated parameter fuzzing
Postman Request body manipulation

Python Libraries

Library Version Purpose
requests >=2.28 HTTP API calls
json stdlib Payload construction

References