{"repo":"mschwager/route-detect","free":true,"listed":false,"github":"https://github.com/mschwager/route-detect","clone":"git clone https://github.com/mschwager/route-detect.git","description":"Find authentication (authn) and authorization (authz) security bugs in web application routes.","language":"Python","stars":280,"topics":["authentication","authorization","http-server","routes","security","static-analysis"],"license":"BSD-3-Clause","category":"auth-billing-email","readme_excerpt":"route-detect Find authentication (authn) and authorization (authz) security bugs in web application routes: Routes from koel streaming server Web application HTTP route authn and authz bugs are some of the most common security issues found today. These industry standard resources highlight the severity of the issue: - 2021 OWASP Top 10 #1 - Broken Access Control - 2021 OWASP Top 10 #7 - Identification and Authentication Failures (formerly Broken Authentication) - 2023 OWASP API Top 10 #1 - Broken Object Level Authorization - 2023 OWASP API Top 10 #2 - Broken Authentication - 2023 OWASP API Top 10 #5 - Broken Function Level Authorization - 2023 CWE Top 25 #11 - CWE-862: Missing Authorization - 2023 CWE Top 25 #13 - CWE-287: Improper Authentication - 2023 CWE Top 25 #20 - CWE-306: Missing Authentication for Critical Function - 2023 CWE Top 25 #24 - CWE-863: Incorrect Authorization Supported web frameworks Language Framework Semgrep CodeQL --------------------- --------------------- ------- ------ Python Django ✅ ❌ Python Django REST framework ✅ ❌ Python Flask ✅ ❌ Python Sanic ✅ ❌ Python FastAPI ✅ ❌ PHP Laravel ✅ ❌ PHP Symfony ✅ ❌ PHP CakePHP ✅ ❌ Ruby Rails ❌ ✅ Ruby Grape ✅ ❌ Java JAX-RS ✅ ❌ Java Spring ✅ ❌ Go Gorilla ✅ ❌ Go Gin ✅ ❌ Go Chi ✅ ❌ JavaScript/TypeScript Express ✅ ❌ JavaScript/TypeScript React ✅ ❌ JavaScript/TypeScript Angular ✅ ❌ Installing Use pip to install route-detect : You can check that route-detect is installed correctly with the following command: Using route","default_branch":null,"files":null,"tree":[],"storefront":"/r/mschwager","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mschwager/route-detect/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}