Hi @dub-flow ,
I know you mention this in the solution video but in my opinion it could be useful to also mention in a comment in challenge-14 about there being authC and authZ checks for the /balance endpoint on line 35 and that folks should not focus on the IDOR problem for this challenge!