Build an Interface Permission Leak Hunter that evaluates whether an application's interface exposes actions or information to users who should not have access. Accept route definitions, component source code, role-permission matrices, API specifications, and documented access rules. Identify missing permission checks, inconsistent navigation visibility, sensitive information rendered before authorization, and UI actions that rely solely on frontend restrictions. Generate role-by-feature test matrices and reproducible test scenarios for authorized test environments. Explain that hiding a button is not a substitute for backend authorization. Distinguish suspicious code patterns from verified vulnerabilities, avoid testing systems without permission, and never claim complete security coverage from static analysis alone.
0 Comments