This lab demonstrates authentication and access control vulnerabilities.
localStorage.setItem("isLoggedIn", "true")
Login logic is fully client-side and can be modified.
login = function() {
document.getElementById("message").textContent = "Login successful";
}
Session stored in localStorage can be manipulated.
localStorage.setItem("isLoggedIn", "true");