6 distinct issuesGrouped by rule across all scanned pages, worst severity first. Click the severity pills above to filter.
All issues are hidden by the severity filter — click the pills above to re-enable tiers.
criticalsecuritysecurity/authn2 pages
Unknown token falls back to admin user instead of 401
When the token role doesn't match any DEMO_USERS entry, the function returns DEMO_USERS[0] (likely the admin user) instead of raising 401. Any authenticated-looking request with an unrecognized 'Bearer ' token gains admin privileges, enabling full privilege escalation past require_role checks.
[
{
"url": "backend/app/auth.py",
"severity": "critical",
"title": "Unknown token falls back to admin user instead of 401",
"evidence": {
"selector": "backend/app/auth.py:19",
"snippet": " return DEMO_USERS[0]",
"note": "Base raised HTTPException(status_code=401, detail=\"Unknown token\") instead."
}
},
{
"url": "backend/app/auth.py",
"severity": "serious",
"title": "Prefix check weakened to accept any 'Bearer ' token",
"evidence": {
"selector": "backend/app/auth.py:13",
"snippet": " if not authorization or not authorization.startswith(\"Bearer \"):",
"note": "Base checked startswith(TOKEN_PREFIX) which enforces the demo-token- format."
}
}
]
seriouscodecode/regression8 pages
Admin nav gate checks session existence, not role
The filter for adminOnly routes was changed from checking session?.user.role === 'admin' to session !== null, so any authenticated non-admin user now sees and can click the Admin nav link. Restore the role check.
[
{
"url": "backend/app/main.py",
"severity": "serious",
"title": "SQL built by string interpolation",
"evidence": {
"source": "backend/app/main.py",
"line": 175,
"snippet": "rows = conn.execute("
}
},
{
"url": "backend/app/main.py",
"severity": "serious",
"title": "SQL built by string interpolation",
"evidence": {
"source": "backend/app/main.py",
"line": 191,
"snippet": "rows = conn.execute("
}
},
{
"url": "backend/app/main.py",
"severity": "serious",
"title": "SQL built by string interpolation",
"evidence": {
"source": "backend/app/main.py",
"line": 316,
"snippet": "rows = conn.execute(f\"SELECT * FROM orders {where} ORDER BY id DESC\", params).fetchall()"
}
}
]
serioussecuritysecurity/authorization1 page
Viewer role granted edit/create UI controls
hasRole('editor','admin','viewer') now grants canEdit to viewers, exposing 'New product' and 'Edit' buttons and allowing PATCH/POST calls to /products for unauthorized users. Revert to hasRole('editor','admin').
Unsanitized route data injected via innerHTML in nav rendering
route.label and route.hash are interpolated directly into innerHTML without escaping. While current ROUTES are static, this pattern is unsafe and flagged by Tier-0 as an XSS vector; any future dynamic route data (e.g., from server config) would allow script injection. Use escapeHtml or safe DOM construction.