feat(skill): tenant-aware-cache-key-review — reviews multi-tenant caches for tenant context omission and authorization bypass - #3070
Closed
Mystic-commits wants to merge 1 commit into
Conversation
…hes for tenant context omission and authorization bypass
|
Thanks for the submission! 🙏 SecuritySkills is now issue-first: contributions need a linked issue that a maintainer has marked approved before a PR is opened. Please open an issue describing the skill, wait for the |
2 of 4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR does
Adds the dedicated
tenant-aware-cache-key-reviewAppSec skill for multi-tenant applications and cache-backed APIs. Reviews caching layers (Redis, Memcached, DynamoDB DAX, in-memory caches, GraphQL DataLoaders, and shared CDN/edge caches) for tenant context omissions, authorization bypass on cache hit, cross-tenant cache pollution, and role/privilege leakage.Linked approved issue (required for new skills)
Closes #3071
Closes #2416
Type of change
Reproduction — independently runnable (required)
Mystic-commits/SecuritySkills@08c30d5c273a2185857300b4c6cd12593af1b4faDiscrimination evidence — true positive AND true negative (required)
file:line:tests/fixtures/tenant-aware-cache-key-review/tenant-context-drop-vulnerable/routes.js:12— correctly detectscacheKey =project:${projectId};omittingtenantIdandrole, causing cross-tenant and privilege leakage (OWASP-API-Security-2023 API1/API3, CWE-639, CWE-863). Includes verified auto-fix regression diff inmanifest.yaml.file:line:tests/fixtures/tenant-aware-cache-key-review/tenant-isolated-key-benign/routes.js:12— correctly passes with 0 findings when cache key explicitly bindstenantId,projectId, androlewithCache-Control: private, no-store.Framework grounding
Attestation & checklist
SKILL.mdfrontmatter is complete andname:matches the skill's directory.skills/and existing open PRs — this is not a duplicate of a shipped skill. (Supersedes closed stale PRs Add tenant-aware cache key review skill #2441 and Add tenant-aware cache key review skill #2573, and replaces incomplete PR feat(skill): tenant-aware-cache-key-review — reviews cache keys for tenant leakage #2580 with a 100% compliant, 5/5 quality-scored implementation).author:is my own GitHub handle (Mystic-commits).Anything else for a reviewer
docs/quality-scorecard.md.patterns.md(Node, Python, Go, GraphQL DataLoader, and Edge CDN rules) andchecklist.md.git diff --checkpasses).