access-control
Safeguard articles tagged "access-control" — guides, analysis, and best practices for software supply chain and application security.
60 articles
Soft-Deleted Records Are Still Reachable
A soft delete sets a flag and leaves the row in place, which means every single query, export, search index, and cache that touches that table has to remember to exclude it. One that does not is a path where a user's deletion was never actually honored.
Your Access Review Checks One Node in a Graph
A user's permission listing shows no administrative access. By every direct check, they are ordinary. They can still become an administrator through a permission that looks unrelated, was granted for an unrelated reason, and lets them modify something that leads there.
A Revocation Is Not Effective Until Every Cache Agrees
You remove a vendor's IP from an allowlist and the firewall updates immediately. It does not update every client that already resolved the hostname and cached the answer, some of which will keep connecting to the old address for as long as their TTL says they may.
Just-in-Time Provisioning Moves Trust From a Person to a Claim in a Token
A new employee signs in with SSO for the first time, and your application creates an account and assigns a role based on group claims from the identity provider, with no human in the loop to notice if the claim maps to more access than intended.
Nobody Chose to Fail Open. The Catch Block Did.
A permission check that throws, times out, or returns something unexpected proceeds as though access were granted, because a broad catch block written to handle an operational problem silently became an authorization bypass.
Anyone With the Link Is Not an Access Control
It is the absence of one, with a long identifier standing in for a decision about who should see the thing. Products ship it because customers need it, and then nobody can list what has been shared.
The Invitation Flow Is an Access Grant Wearing a Growth Feature's Interface
Someone mistypes a colleague's address and a stranger is in that company's tenant, because the invitation worked exactly as designed. It is built early, for frictionlessness, by whoever shipped the collaboration feature.
A Presigned URL Is a Capability You Minted Without Thinking About It
Anyone holding the string can do what it permits, with no identity check, until it expires. Every mistake is a variation of one thing: handing out more capability than intended, for longer than intended.
Permission Models Are Not Designed, They Accumulate
An is_admin boolean, then a role column, then a special case for one customer. Three years later nobody can say what a given user can do without reading the code, and an auditor is asking.
When NULL Tenant Means Global, Forgetting the Tenant Means Disclosure
A nullable tenant_id where NULL means global makes omission the unsafe state, and SQL NULL semantics mean the mistake never raises an error. The admin view looks full and correct while tenant-scoped rows are simply absent.
A Sudo Bug Let Local Users Reach Root Without Ever Appearing in Sudoers
CVE-2025-32463 let any local user leverage sudo's --chroot option to run commands as root, bypassing the sudoers access-control model entirely.
A Joomla Editor and a Magento Cache Warmer Both Delivered Unauthenticated RCE at 9.8
Widget Factory's JCE editor and Mirasvit's Full Page Cache Warmer reached identical maximum severity through completely different root causes — a missing permission check and a PHP deserialization flaw.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.