Verify an AI-Flagged Auth Bug
Validate an AI-generated authorization warning using a control and test proof path.
AI flags an authorization bypass on GET /projects/:projectId/export. ASVS-style check: protected object, actor, server-side control, negative proof. Treating "admin-only" as true because a nearby route uses an admin guard. Object Protected object: project export. User-controlled identifier: projectId from the route. Authorization review starts by naming what resource is being accessed and who supplies the selector. Control The new route checks requireLogin but does not call requireProjectAdmin before exportProject(projectId). Authentication proves identity; authorization proves permission for this object. They are not interchangeable. Proof Existing tests cover logged-out users but not logged-in users from another project. Request a cross-project denial test. A…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in