Discover a single-page-app's hidden backend API from its public JS bundle, then test that API for broken access control / missing authentication.