Skip to main content
AI-CODE-REVIEW5 MIN READ

Verify an AI-Flagged Auth Bug

Validate an AI-generated authorization warning using a control and test proof path.

AI flags an authorization bypass on GET /projects/:projectId/export. ASVS-style check: protected object, actor, server-side control, negative proof. Treating "admin-only" as true because a nearby route uses an admin guard. Object Protected object: project export. User-controlled identifier: projectId from the route. Authorization review starts by naming what resource is being accessed and who supplies the selector. Control The new route checks requireLogin but does not call requireProjectAdmin before exportProject(projectId). Authentication proves identity; authorization proves permission for this object. They are not interchangeable. Proof Existing tests cover logged-out users but not logged-in users from another project. Request a cross-project denial test. A…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us