Mobile API and deep-link boundaries
Map deep links to their app routes and API calls, then test validation of host, path, parameters, and login state in an emulator with accounts you control. Avoid testing links delivered to real users.
Level: advanced
Tools: Android Studio, adb, Burp Suite
Pipeline
adb shell am start -W -a android.intent.action.VIEW -d '{deep_link}'; capture the resulting controlled-app request and verify the server enforces the same authorization as the UI.