Auditor
List endpoints enforce a maximum page size and cannot dump whole collections.
1.1.1: a callee whose root is a name that `Object.prototype` also carries (`build().toString()` tokenizes to the bare callee `toString`; also `constructor`, `valueOf`, `hasOwnProperty`) was looked up in the plain object that holds the imported names, so it resolved to the INHERITED FUNCTION instead of to nothing and the whole check died with "name.includes is not a function". Only a real binding counts now, and the name of a unit is always read as a string. Found on a 1 319-file checkout (2fa-available and session-expiry-rotation, 2026-09-24); the same line was in the 15 scripts that walk the call graph, so all fifteen ship the fix. (1.1.0: deterministic: the rule runs over the static analysis kit (tokens, function units, calls, imports, routes) with no AI engine; exact decisionRule and languages published; not-applicable with the reason when the checkout gives nothing to evaluate. A list handler reads a collection in its body or through a callee whose result reaches the response (data-layer receivers only; single-record reads and third-party API calls excluded); pagination or clamp is searched in the handler, the read arguments and the callees; DRF PAGE_SIZE and Laravel $perPage count as a framework page size. Not judged: table size, external data layers. (1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)))
| // a list handler is a route FUNCTION UNIT (kit) that reads a collection itself or through a callee (<= 2 module hops) |
| const LIST_METHOD_STRONG = /^(?:findMany|findAll|getAll|listAll|fetchAll|scan|toArray)$/; // anywhere |
| const LIST_METHOD_WEAK = /^(?:find|list|all|get|query|filter|select|search)$/; // only on a dao/repo/model/db receiver, never with a single id |
| const PAGINATION = /\b(?:limit|take|per_?page|page_?size|paginate|cursor|offset|skip)\b|\[\s*:\s*\d+\s*\]|\.limit\s*\(/i; // absent in handler + read args + callees and no DRF PAGE_SIZE / $perPage -> HIGH |
| const CLAMP = /Math\.min\s*\(|\bmin\s*\(|\bclamp\s*\(|MAX_(?:PAGE|LIMIT|PER_PAGE)\w*|[<>]=?\s*MAX\w*|\.max\(\s*\d+|paginate\s*\(\s*\d+/i; // page size from the request without it -> MEDIUM |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.