1. Log in as the normal user. *IDOR: /api/user/1 returns the admin user's record including their api_token (your id is 2; id 1 isn't checked). Why:* object-level authz is missing.
2. *Escalate:* call /api/admin with header Authorization: Bearer <that token>. The admin token is accepted and the endpoint returns the flag. Run solve.py to do both steps.
Lesson: one access-control gap feeds the next β defend every layer.