Master Secure Coding

Master Secure Coding

Level up your security skills with hands-on code review challenges. Identify and fix vulnerabilities to become a better engineer.

Challenge of the WeekMedium
150 points

Patient Records

Review code for MedLedger, a healthcare data platform that manages patient medical records across multiple hospital departments. The API allows clinicians to access and update patient information using JWT authentication. The system assumes tokens are pre-verified by an upstream gateway. Examine how the API extracts and validates clinician identity to ensure proper access controls are enforced.

APIGOJWT (JSON WEB TOKENS)

Vulnerable Code

go

Instructions:

  1. Browse through the files to understand the application structure
  2. Find and click on the line containing the vulnerability
  3. Click "Check Line" to verify your answer
ENTERPRISE SOLUTION

Secure Your Engineering Team

Build a security-first culture with our enterprise training platform. Custom challenges, team analytics, and dedicated support for your organization.

Team Dashboard

Track progress and manage users with ease

Custom Challenges

Tailored to your tech stack and industry

SSO Integration

Seamless authentication for your team

Priority Support

Dedicated account manager and SLA

Ready to scale security training?

Join leading companies who trust us to train their engineering teams on secure coding practices.

Contact Sales

Volume-based pricing available