The authentication endpoints (login, registration, password reset, OTP, token, OAuth, MFA) and the data endpoints are protected by a rate-limiting mechanism whose scope actually covers each of them. No AI engine is involved: the verdict is reproducible from the source alone.
Inputs
Non-test code files of the checkout (JavaScript, TypeScript, Python, PHP) for the route inventory and the call graph, plus dependency manifests, nginx, Terraform, serverless/CloudFormation and wrangler files for the mechanism, analysed statically with the platform kit: tokens, function units, calls, imports and route registrations of Next (app and pages), Express, Fastify, Koa, Hono, Nest, Lambda, Django (views and urls.py), Flask, FastAPI and Laravel. An authentication endpoint is a route whose path segments, handler or controller name say login, sign-in, logout, register (registration is its own class), password, forgot, reset-password, recover, OTP, 2FA, MFA, TOTP, magic link, verify-email, impersonate, or a token, refresh, session, verify, confirm, callback, authorize, code, challenge, passkey segment inside an auth, oauth, sso, saml, oidc, account, identity, session or connect path. A registration or verification endpoint has a register, signup, join, onboard, invite, activate, confirm-email, resend, verify or subscribe segment. A data endpoint reads a collection (findMany, findAll, getAll, objects.all/filter, ::all/::get, ->get(), SELECT … FROM, find({}), scan, paginate) in the handler or a function it calls within 2 module hops, or answers with a strong personal-data field. Coverage per route: a limiter among the route middleware or decorators (Express arguments, Laravel throttle:, @limiter.limit, @ratelimit, throttle_classes, Nest @Throttle), on the class (UseGuards(ThrottlerGuard), throttle_classes), a limiter call in the handler or its callees within 2 module hops (rateLimiter.check, limiter.consume, RateLimiter::attempt, an in-handler counter answering 429), app.use(limiter) registered earlier in the same file (token order, prefix honoured), or a framework-wide mechanism whose scope covers the path: a Next.js middleware/proxy with a limiter and a matcher that includes the route (an api-key strategy with limits counts for its prefix), app.use(rateLimit()) in an entry file, Nest ThrottlerGuard as APP_GUARD or useGlobalGuards, DRF DEFAULT_THROTTLE_CLASSES for DRF views, django-ratelimit/axes middleware (axes covers login paths), Flask-Limiter default_limits, slowapi middleware, Laravel Kernel global $middleware or the api/web groups for routes/api.php and routes/web.php, nginx limit_req in the location whose prefix or regex covers the path (or at server level), a WAF rate-based rule or Cloudflare ratelimits binding in versioned infrastructure. Paths listed in excludes are never analysed. Nothing of the checkout is executed.
Decision rule
Not applicable when no HTTP route is declared. FAIL (HIGH, auth-endpoint-not-limited) for each authentication endpoint that no limiter covers; the description says whether a mechanism exists elsewhere in the checkout without covering the route or none is declared at all. A registration or verification endpoint without coverage is MEDIUM (registration-endpoint-not-limited); a data endpoint without coverage is MEDIUM (data-endpoint-not-limited); MEDIUM blocks only in Extended suites. Routes public by design (health/status/metrics, webhooks, OAuth callbacks) are not data endpoints; a data endpoint reachable only with a service secret (a Next.js middleware strategy of kind service, a requireService*/verifyService*/SERVICE_SECRET gate) is an internal endpoint of the platform, listed in the trace and never reported. PASS when every authentication, registration and data endpoint is covered (the summary names each endpoint and the limiter that covers it), or when the inventory holds none of them. Not judged by this check (declared): limiters in infrastructure that is not versioned in the checkout (a managed WAF, an API gateway usage plan, a CDN rule), whether the limiter key can be spoofed (X-Forwarded-For trusted), the numbers of the limit, and internal service-to-service data endpoints.
Type
deterministic
1.1.1: a callee whose root is a name that `Object.prototype` also carries (`build().toString()` tokenizes to the bare callee `toString`; also `constructor`, `valueOf`, `hasOwnProperty`) was looked up in the plain object that holds the imported names, so it resolved to the INHERITED FUNCTION instead of to nothing and the whole check died with "name.includes is not a function". Only a real binding counts now, and the name of a unit is always read as a string. Found on a 1 319-file checkout (2fa-available and session-expiry-rotation, 2026-09-24); the same line was in the 15 scripts that walk the call graph, so all fifteen ship the fix. (1.1.0: deterministic: the rule runs over the static analysis kit (tokens, function units, calls, imports, routes) with no AI engine; exact decisionRule and languages published; not-applicable with the reason when the checkout gives nothing to evaluate. Per-route coverage (route middleware, class, in-handler limiter calls including 429 counters, app.use before the route, Next.js middleware matcher, APP_GUARD ThrottlerGuard, DRF and axes, Flask-Limiter, Laravel Kernel groups, nginx limit_req locations, WAF rules); authentication endpoints by strict path segments (HIGH), registration and client data endpoints MEDIUM. Not judged: service-to-service data endpoints, limiters in infrastructure not versioned in the checkout. (1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)))
// routes are FUNCTION UNITS of the static analysis kit; coverage is decided PER ROUTE, never by a mechanism existing somewhere
const AUTH_WEAK_SEGMENT = /^(?:token|refresh|session|verify|confirm|callback|authorize|code|challenge|passkey)$/i; // only inside an auth|oauth|sso|account|identity path