AI-written code passed tests and review but missed an authz check, leaking user records

Mangwe_Tanser · reddit · 2026-09-11

A developer shares a real incident: an AI-written endpoint shipped a few weeks ago let any logged-in user read other users' records. It passed tests and two-person PR review — the ownership check simply wasn't there, and nobody caught it in the diff.

Key observations from the post:

The author asks the community for practices that actually catch these holes before merge, not policy-doc platitudes.

Original post →

More from coding & agent

coding & agent channel →