Threat modeling lab - Last Flag

Hey there - we’ve reviewed your JSON and confirmed that the grader was failing for the following reasons:

  • Your “Workshop API” was outside of the “Data Center (Protected)” trust boundary.
  • You spelled “access” as “acces” in two places in the “Server-Side Request Forgery” threat.

That said, your model was correct otherwise, so I’ve messaged the flag to you.

1 Like