LogicGuard inspects execution graphs across multi-file pull requests to eliminate authorization bypasses, multi-tenant boundary leaks, and IDOR flaws that static linters miss.
feat/billing-agg → main
| 18 | export async function getInvoiceRecord(req: Request, res: Response) { | |
| 19 | // Extract unauthenticated payload parameter | |
| 20 | const { invoiceId } = req.params; | |
| 21 | ||
| 22 | - | // ❌ CWE-639 / BOLA: Direct lookup without tenant predicate allows cross-tenant exfiltration |
| 23 | - | const invoice = await prisma.invoice.findUnique({ where: { id: invoiceId } }); |
| 22 | + | // ✅ LOGICGUARD REPAIR: Scoped query bound to verified JWT tenant context |
| 23 | + | const { tenantId } = req.auth; // Enforces strict multi-tenant boundary |
| 24 | + | const invoice = await prisma.invoice.findFirstOrThrow({ |
| 25 | + | where: { id: invoiceId, tenantId: tenantId } |
| 26 | + | }); |
| 27 | ||
| 28 | return res.json(invoice); | |
| 29 | } |
Route: GET /api/v1/invoices/:invoiceId → Parameter req.params.invoiceId marked as untrusted user controlled.
Flow passes into InvoiceService.lookup(). Auth token exists on session (req.auth.tenantId), but parameter is dropped before ORM builder.
Sink: prisma.invoice.findUnique({ where: { id } }). Violation: Invariant 'INV-TENANT-ISOLATION' requires scoped predicate tenantId == req.auth.tenantId on all multi-tenant models.
# Auto-generated by LogicGuard Enclave v0.9 (PR #214 Exploit Reproducer)
import pytest
from httpx import AsyncClient
@pytest.mark.security
@pytest.mark.cwe(639)
async def test_cross_tenant_invoice_idor_blocked(api_client: AsyncClient, seed_tenants):
"""
INVARIANT ASSERTION:
Tenant A user must NEVER retrieve Tenant B invoice records,
even if Tenant A has knowledge of valid Tenant B UUIDs.
"""
tenant_a_token = seed_tenants["tenant_alpha"].auth_token
tenant_b_invoice_id = seed_tenants["tenant_beta"].invoices[0].id
# Issue cross-tenant query with Tenant A credentials:
response = await api_client.get(
f"/api/v1/invoices/{tenant_b_invoice_id}",
headers={"Authorization": f"Bearer {tenant_a_token}"}
)
# PR #214 unpatched code returned 200 OK (LEAK PROVEN).
assert response.status_code in [403, 404], (
f"CWE-639 EXPLOIT CONFIRMED: Cross-tenant data returned: {response.json()}"
)
Drafted automatically by LogicGuard Bot in response to blocked PR #214. Remediates CWE-639 / BOLA vulnerability by injecting authenticated tenant predicate into Prisma query.
logicguard/remediate-cwe-639
•
Target: feat/billing-agg
•
✓ All 14 test suites & synthesized exploit test passing
Generated regression test: tests/security/tenant_isolation_test.py
Automated Fix PR #215 drafted with scoped query patch.
Traditional linters evaluate single lines in isolation. LogicGuard builds inter-procedural AST call graphs to trace authorization context across the entire repository.
Tracks untrusted request parameters across controllers, service boundaries, and ORM calls rather than isolated single-line regex matches.
Never fires unvalidated alerts. LogicGuard synthesizes an isolated unit test reproducing the bypass before flagging the PR.
Emits precise, AST-validated pull requests directly into GitHub/GitLab, keeping review velocity high while locking down invariants.
Traditional code scanners look for known vulnerable function signatures (eval(), exec()). Business logic flaws are syntactically valid code that violates semantic security invariants.
| Security Invariant / Capability | Legacy Linters & SAST | LogicGuard AST Engine |
|---|---|---|
|
Broken Object Level Auth (BOLA / IDOR)
CWE-639 • Accessing resource IDs without tenant checks
|
Misses cross-file context | Blocked via AST Taint Graph |
|
Multi-Tenant Boundary Leaks
CWE-285 • Cross-organization data aggregation or joining
|
Blind to SQL / ORM scopes | Enforces composite tenant predicates |
|
Verification via Test Synthesis
Synthesizing runnable unit tests proving exploitability
|
Unsupported (heuristic alerts) | Generates pytest / Vitest reproducer |
|
Automated Fix Generation
Producing branch-ready pull requests with correct types
|
Generic regex suggestions | Drafts ready-to-merge Fix PR |
|
False Positive Rate
Signal-to-noise ratio in developer pull requests
|
High (35% – 60% alert fatigue) | 0.0% (Gated by synthesized test pass) |
Write rules once in .logicguard/invariants.yaml. LogicGuard compiles them into AST traversal rules that execute across every pull request.
# LogicGuard Invariant Specification v2026.1
version: "2026.1"
enforcement_policy:
fail_mode: BLOCK_PULL_REQUEST
synthesize_exploit_test: true
auto_draft_remediation_pr: true
invariants:
- id: "INV-TENANT-ISOLATION"
cwe: "CWE-639"
description: "ORM queries must bind req.auth.tenantId on multi-tenant entities."
targets:
- "prisma.*.findUnique"
- "prisma.*.findMany"
- "typeorm.*.findOne"
taint_rules:
untrusted_source: "req.params.*"
required_predicate: "where.tenantId == req.auth.tenantId"
test_synthesis:
framework: "pytest"
mock_tenants: 2
Repositories are processed ephemerally in isolated secure enclaves. Your proprietary source code is never used for training foundation models.
Ephemeral, memory-only execution environments with cryptographic attestation and zero persistent disk storage.
Customer AST trees and source diffs are purged upon scan completion. No weights are modified using private customer code.
Deploy the LogicGuard AST daemon inside your own VPC or air-gapped Kubernetes cluster with zero external egress.
Enterprise audit-ready controls with mutual TLS 1.3, ephemeral key pairs, and role-based access control.
Runs natively inside your PR check suite. Evaluates the full execution graph before developer review starts.
gh extension install logicguard/cli