Auditor
CORS allows only declared origins; no wildcard with credentials.
1.0.3: credentials for a manual `Access-Control-Allow-Origin` header used to be read against the WHOLE file: a helper with two independent `if`/`else` branches — one returning a bare wildcard with no credentials, the other a validated origin WITH credentials — had its wildcard branch reported HIGH just because the word appeared elsewhere in the file. `credentials` (and the existing `reflected` look-back window) is now read from the enclosing `{...}` block the header write itself belongs to (a brace-balanced walk outward, capped, falling back to a bounded window when the header sits outside any braces at all — sequential `header()` calls in PHP/nginx), so two branches that never execute together are judged separately. A wildcard and credentials written into the SAME object or the same function body still fail (planted case: `res.writeHead(200, { 'Access-Control-Allow-Origin': '*', 'Access-Control-Allow-Credentials': 'true' })` stays HIGH). (1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).))
| wildcard: /origin\s*:\s*['"]\*['"]/.test(options) || options === 'true', |
| reflected: /origin\s*:\s*(?:true|req\.headers\.origin|\(\s*origin\s*,\s*cb\s*\)\s*=>\s*cb\(\s*null\s*,\s*true\s*\))/.test(options), |
| credentials: /credentials\s*:\s*true/.test(options), |
| // wildcard or reflected + credentials -> FAIL (HIGH); open origin without credentials or an unconfigured cors() -> MEDIUM |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.