review
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
SecuritySecurityevals/cases.yaml
MEDIUMSecurityMEDIUM
evals/cases.yaml
Blocker: The route allows any authenticated user to fetch any invoice by ID, violating the 'view their own invoices' requirement. Implement an owner-scoped query and return 404 for non-accessible resources to prevent data leakage. Add targeted tests to prove cross-user access is blocked before shipping.
Confidence: 72%Severity: 82%
Audit Metadata