This lab contains an access control vulnerability where sensitive information is leaked in the body of a redirect response.
I solve the lab, obtain the API key for the user carlos and submit it as the solution.
I logged in to your own account using the following credentials: wiener:peter