Authorization and access control security guidance based on Project CodeGuard — covers RBAC/ABAC/ReBAC, IDOR prevention, mass assignment, and transaction authorization
87
82%
Does it follow best practices?
Impact
93%
1.45xAverage score across 6 eval scenarios
Passed
No findings from the security scan
Matrix is YAML or JSON
100%
100%
Tests iterate the matrix
66%
100%
Deny-by-default reflected
88%
100%
Security notes present
85%
100%
Prefer ABAC/ReBAC noted
13%
100%
ABAC or ReBAC implementation
100%
100%
Centralized authorization
77%
100%
Generic 403/404 on denial
0%
88%
Sequential IDs flagged
0%
100%
Ownership-verified document access
100%
100%
Security comments
100%
100%
UUID/non-enumerable IDs noted
0%
100%
No resource existence leak
33%
100%
Extra fields config fixed
100%
100%
Merge logic hardened
100%
100%
Input validation on permitted fields
51%
82%
Brute-force throttling
0%
96%
Flow restart on failure
0%
98%
Deny-by-default structure
100%
100%
Denial log includes resource identifier
73%
100%
Denial log includes rationale code
83%
100%
Centralized authorization enforcement
96%
100%
Deny-by-default structure
86%
100%
Generic error response
63%
100%
Logging does not include PII in log record
83%
100%
Authorization pattern named
73%
100%