<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Jonny</title>
    <description>The latest articles on DEV Community by Jonny (@cbjonny).</description>
    <link>https://dev.to/cbjonny</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4166045%2F7d307208-0252-4621-8da4-34e11534e693.png</url>
      <title>DEV Community: Jonny</title>
      <link>https://dev.to/cbjonny</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/cbjonny"/>
    <language>en</language>
    <item>
      <title>Catch unintended authz changes</title>
      <dc:creator>Jonny</dc:creator>
      <pubDate>Tue, 06 Oct 2026 10:45:13 +0000</pubDate>
      <link>https://dev.to/cbjonny/catch-unintended-authz-changes-421b</link>
      <guid>https://dev.to/cbjonny/catch-unintended-authz-changes-421b</guid>
      <description>&lt;p&gt;Hi all,&lt;/p&gt;

&lt;p&gt;I'm co-founder of &lt;a href="https://counterbranch.com" rel="noopener noreferrer"&gt;counterbranch&lt;/a&gt;, and we're on a mission to help developers catch unintended access control change.&lt;/p&gt;

&lt;p&gt;For each pull request in your repository, the action creates one comment and updates it on every run. It states the result first, links the source at both revisions, and attaches the full report as a ZIP you can manually inspect as the reviewer, or hand to your coding agent.&lt;/p&gt;

&lt;p&gt;We've just &lt;a href="https://github.com/marketplace/actions/counterbranch-access-control-change-review" rel="noopener noreferrer"&gt;released on GitHub Marketplace an alpha-version GitHub action&lt;/a&gt; you can put in your current workflow to help identify changes to authz schema. &lt;/p&gt;


&lt;div class="ltag-github-readme-tag"&gt;
  &lt;div class="readme-overview"&gt;
    &lt;h2&gt;
      &lt;img src="https://assets.dev.to/assets/github-logo-5a155e1f9a670af7944dd5e12375bc76ed542ea80224905ecaf878b9157cdefc.svg" alt="GitHub logo"&gt;
      &lt;a href="https://github.com/counterbranch" rel="noopener noreferrer"&gt;
        counterbranch
      &lt;/a&gt; / &lt;a href="https://github.com/counterbranch/action" rel="noopener noreferrer"&gt;
        action
      &lt;/a&gt;
    &lt;/h2&gt;
    &lt;h3&gt;
      GitHub Action for reviewing authorization changes.
    &lt;/h3&gt;
  &lt;/div&gt;
  &lt;div class="ltag-github-body"&gt;
    
&lt;div id="readme" class="md"&gt;&lt;div class="markdown-heading"&gt;
&lt;h1 class="heading-element"&gt;Counterbranch scanner Action&lt;/h1&gt;
&lt;/div&gt;
&lt;p&gt;Compare static authorization coverage between two Git revisions and review the
result in your pull request. The scanner examines source without executing your
application. Findings are advisory; they do not prove runtime enforcement.&lt;/p&gt;
&lt;div class="markdown-heading"&gt;
&lt;h2 class="heading-element"&gt;What it checks&lt;/h2&gt;
&lt;/div&gt;
&lt;p&gt;Counterbranch compares recognized authorization-related source evidence between
the pull request's merge base and head.&lt;/p&gt;
&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Change or situation&lt;/th&gt;
&lt;th&gt;What the report tells you&lt;/th&gt;
&lt;th&gt;Why it matters&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;A recognized guard or authentication check is added, removed, or changed&lt;/td&gt;
&lt;td&gt;The affected operation's before-and-after static evidence&lt;/td&gt;
&lt;td&gt;Review whether the change matches the intended access rules.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;A role, permission declaration, or captured authorization hint changes&lt;/td&gt;
&lt;td&gt;The declaration or evidence recorded by the scanner that changed, where recognized&lt;/td&gt;
&lt;td&gt;Access-related code can change while the endpoint list stays the same.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;An endpoint is added or removed&lt;/td&gt;
&lt;td&gt;The added or removed operation, with revision-specific source links&lt;/td&gt;
&lt;td&gt;Review access expectations alongside changes to the API.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;An endpoint’s method, path, or&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;…&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class="gh-btn-container"&gt;&lt;a class="gh-btn" href="https://github.com/counterbranch/action" rel="noopener noreferrer"&gt;View on GitHub&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;


&lt;p&gt;Right now it supports the popular frameworks / libraries: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Policy Engines (OPA, Cedar, OpenFGA)&lt;/li&gt;
&lt;li&gt;Custom AuthZ (Express, NestJS, Django, Django REST framework, FastAPI, Flask, and Spring MVC).&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;"But don't policy engines include native test runners?"&lt;br&gt;
Yes, but it's complementary / runs alongside.  We're looking for changes to authz in application code, sometimes when the policy hasn't changed.&lt;/p&gt;

&lt;p&gt;We appreciate any and all feedback while we alpha test this tool and further expand! You can also join the list for updates &lt;a href="https://counterbranch.com/#updates" rel="noopener noreferrer"&gt;here&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
      <category>testing</category>
      <category>showdev</category>
      <category>githubactions</category>
    </item>
  </channel>
</rss>
