sharp-edges
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
SecuritySecurityreferences/auth-patterns.md
MEDIUMSecurityMEDIUM
references/auth-patterns.md
The fragment provides severe authentication and authorization anti-patterns: IDOR via untrusted user_id object lookups, MFA bypass risks due to frontend-only enforcement and weak/spoofable device-token derivation, and account takeover via predictable, non-invalidated recovery codes with effectively unlimited guessing attempts. There is no clear evidence of supply-chain malware (e.g., payload execution, persistence, exfiltration, or obfuscation); the risk is extremely high from broken authz/authn design if implemented as shown.
Confidence: 70%Severity: 90%
Audit Metadata