DEV Community

Cover image for Catch unintended authz changes
Jonny
Jonny

Posted on AI-assisted

Catch unintended authz changes

Hi all,

I'm co-founder of counterbranch, and we're on a mission to help developers catch unintended access control change.

For each pull request in your repository, the action creates one comment and updates it on every run. It states the result first, links the source at both revisions, and attaches the full report as a ZIP you can manually inspect as the reviewer, or hand to your coding agent.

We've just released on GitHub Marketplace an alpha-version GitHub action you can put in your current workflow to help identify changes to authz schema.

GitHub logo counterbranch / action

GitHub Action for reviewing authorization changes.

Counterbranch scanner Action

Compare static authorization coverage between two Git revisions and review the result in your pull request. The scanner examines source without executing your application. Findings are advisory; they do not prove runtime enforcement.

What it checks

Counterbranch compares recognized authorization-related source evidence between the pull request's merge base and head.

Change or situation What the report tells you Why it matters
A recognized guard or authentication check is added, removed, or changed The affected operation's before-and-after static evidence Review whether the change matches the intended access rules.
A role, permission declaration, or captured authorization hint changes The declaration or evidence recorded by the scanner that changed, where recognized Access-related code can change while the endpoint list stays the same.
An endpoint is added or removed The added or removed operation, with revision-specific source links Review access expectations alongside changes to the API.
An endpoint’s method, path, or
…

Right now it supports the popular frameworks / libraries:

  • Policy Engines (OPA, Cedar, OpenFGA)
  • Custom AuthZ (Express, NestJS, Django, Django REST framework, FastAPI, Flask, and Spring MVC).

"But don't policy engines include native test runners?"
Yes, but it's complementary / runs alongside. We're looking for changes to authz in application code, sometimes when the policy hasn't changed.

We appreciate any and all feedback while we alpha test this tool and further expand! You can also join the list for updates here.

Top comments (0)