Skip to content

Add agentic stale OAuth scope authorization drift risk to API3 and API5#146

Open
balaakasam wants to merge 2 commits intoOWASP:masterfrom
balaakasam:agentic-stale-oauth-scope-docs
Open

Add agentic stale OAuth scope authorization drift risk to API3 and API5#146
balaakasam wants to merge 2 commits intoOWASP:masterfrom
balaakasam:agentic-stale-oauth-scope-docs

Conversation

@balaakasam
Copy link

This PR addresses the gap where stale or over-privileged OAuth scopes in agentic systems can bypass function-level authorization.

It adds guidance to:

  • API3: Broken Object Property Level Authorization
  • API5: Broken Function Level Authorization

This introduces a new architectural risk pattern involving autonomous agents retaining stale scopes across task boundaries.

@balaakasam
Copy link
Author

Thank you for reviewing. Happy to adjust language or placement to align with project conventions if needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant