A. Security & Data Safety · Prompt 4
Auth, Roles & Admin Route Lockdown
Get the free PDFWhy it matters
Hiding an admin link is not security. If the route or API answers anyone who requests the URL, it is open.
Modeled on
OWASP ASVS access-control and authentication requirements.
How to run this prompt
- Switch to a mode that does not edit files. In Cursor that is Ask or Plan. In Claude Code that is Plan mode.
- Paste the audit prompt. Wait for the report. It must stop and ask which IDs to fix.
- Read the report. Keep the IDs you agree with.
- Switch to a mode that can edit. Paste the fix prompt and the IDs you chose.
- Switch back to the read-only mode and paste the same audit prompt again. Confirm those IDs are gone.
- Cursor: audit in Ask mode or Plan mode. Fix in Agent mode.
- Claude Code: audit in Plan mode (Shift+Tab cycles to it). Fix in Normal mode, which can edit.
- Any other tool: audit in Chat, Discuss, or Plan mode, whichever answers without editing files. If the tool has no such mode, the prompt itself forbids edits. Fix in the mode that is allowed to edit files.
The audit prompt
MODE: AUDIT ONLY. Do not create, edit, or delete any file. Do not run commands
that change anything: no installs, migrations, git commits, deploys, or "--fix" flags.
If your tool has an Ask, Plan, Chat, or Discuss mode, use it for this prompt.
Before you start:
- Tell me the stack you detect (framework, language, database, auth, hosting,
payment provider) and which folders you will review.
- If a check below does not apply to this stack, write "Not applicable" and why.
- If you can run read-only commands, run the ones listed. If you cannot, list them
so I can run them and paste the output.
Auth, Roles & Admin Route Lockdown: what to check
Audit authentication, roles, and admin protection across the UI, the API, and the database. Do not change accounts or sessions.
1. List routes, pages, and API handlers. Mark each public, signed-in, or admin-only. Flag a sensitive handler whose only check is a client redirect or a hidden button.
2. For every admin or privileged handler, show the server-side role check and the file. A menu that is not rendered does not count.
3. Check IDOR: any handler that takes a user, order, or document id must compare it to the session user or an admin role before returning or changing the row.
4. Check whether a user can grant themselves a role through a profile update, a signup field, a JWT claim they can set, or a query parameter.
5. Check password hashing (bcrypt, argon2, or scrypt), session or JWT expiry, and whether logout invalidates the server session or only deletes a client cookie.
6. Check password-reset and email-verification tokens: they should be random, single-use, and short-lived (minutes to about an hour, not days), and bound to one user. Errors should not reveal whether the email is registered.
7. Check OAuth callback URLs for an open redirect and for a missing or unused state parameter.
8. Find default, seeded, or hardcoded admin accounts. Do not print passwords. Say where they are set and whether production startup would still create them.
Evidence rules:
- Every finding cites a file path and line number, or the exact command output used.
- Mark each finding Confirmed (seen in the code) or Needs manual check (depends on
something outside the repo, such as a dashboard setting or production data).
- Never print a full secret. Show the first 4 characters and the location only.
- If you are not sure, say so. Do not invent files, settings, or results.
Severity: Critical = exploitable now, or leaks real data or money. High = serious
with little effort. Medium = weakens defenses or needs a second bug. Low = hygiene.
Report:
- Summary: count of findings by severity.
- Table: ID | Severity | Confirmed? | Finding | Evidence | Why it matters | Suggested fix | Effort
(IDs for this prompt use the prefix P04, for example P04-1, P04-2.)
- Checked and fine: what you verified is already OK.
- Could not check: what I need to look at myself, and where.
Then stop. Do not fix anything. Ask me which IDs I want fixed.