> For the complete documentation index, see [llms.txt](https://simon-6.gitbook.io/simoncyber/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://simon-6.gitbook.io/simoncyber/portswigger-web-academy/api-testing/lab-2.md).

# Lab 2

<figure><img src="/files/aLLl2SXwJ4SRGBeIvDuT" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/cuf4Awcik84KLK0hJuih" alt=""><figcaption></figcaption></figure>

```
OPTIONS /api/products/1/price HTTP/2
Host: 0acc002e03ddfab980d0b75800b900d0.web-security-academy.net
Cookie: session=6zQX9bODZ3jchdrp2vP6jZbfOlhHRWjd
Sec-Ch-Ua-Platform: "Windows"
Accept-Language: en-US,en;q=0.9
Sec-Ch-Ua: "Not-A.Brand";v="24", "Chromium";v="146"
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36
Sec-Ch-Ua-Mobile: ?0
Accept: */*
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: cors
Sec-Fetch-Dest: empty
Referer: https://0acc002e03ddfab980d0b75800b900d0.web-security-academy.net/product?productId=1
Accept-Encoding: gzip, deflate, br
Priority: u=1, i

session_id = 6zQX9bODZ3jchdrp2vP6jZbfOlhHRWjd

```

<figure><img src="/files/UQcwcLHc1B5j9NsAaN2s" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/kvod0RrjAPXLR00k8Bnm" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/5JNNworWoF6gIlaXQw4O" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/vYNjQifMStdpJif4jVI8" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/xXUXrLBRplbr7tilsOx4" alt=""><figcaption></figcaption></figure>
