37signals-rails
Audited by Socket on Sep 16, 2026
2 alerts found:
Anomalyx2The fragment implements a legitimate custom passwordless authentication flow and shows no evidence of malicious supply-chain behavior. It has notable authentication security risks: a globally searched six-digit code without visible rate limiting or uniqueness enforcement, possible email enumeration, tenant-selection assumptions, and unspecified secure-cookie configuration. These issues warrant review and hardening but do not indicate malware.
The code is ordinary Rails multi-tenancy guidance and contains no indicators of malware, data exfiltration, command execution, obfuscation, or sabotage. The primary security concern is missing authorization: any authenticated or unauthenticated caller able to reach these routes may be able to select another account by changing account_id unless authorization is enforced elsewhere. Background-job context preservation also requires verification of the application configuration.