src/scanners/security-scanner.ts:1
[AGENTS: Deadbolt - Trace]logging, sessions
**Perspective 1:** The security scanner doesn't detect session fixation vulnerabilities where session IDs aren't regenerated after login. This allows attackers to fixate a session ID and hijack user sessions after authentication.
**Perspective 2:** The scanner doesn't check for unlimited concurrent sessions per account. Without limits, attackers can maintain multiple active sessions or perform credential stuffing more effectively.
**Perspective 3:** The scanner doesn't detect insecure token refresh mechanisms. Refresh tokens should have limited lifetime, be securely stored, and invalidate old tokens.
**Perspective 4:** The secret logging detection in lines 516-552 only checks for console statements containing specific patterns (sk-, eyJ, AKIA). It misses many other secret patterns like GitHub tokens, Stripe keys, OpenAI keys, and other API keys that could be logged. The detection is also limited to console.log, debug, info, warn, error but not other logging methods.
**Perspective 5:** The scanner doesn't detect log injection vulnerabilities where user input is directly written to logs without sanitization, which could allow attackers to forge log entries or inject malicious content.
**Perspective 6:** The security scanner doesn't check for missing audit logging of critical security events such as authentication attempts, permission changes, admin actions, or data access. These are essential for security monitoring and incident response.
**Perspective 7:** The scanner doesn't check for missing correlation/request IDs in HTTP request handling, which are essential for tracing requests across distributed systems and correlating logs for security investigations.
Suggested Fix
Expand secret pattern detection to include all patterns from SEC rules and check for all console methods. Consider integrating with the modular rule patterns for comprehensive coverage.