Skip to content

Add agentic stale OAuth scope authorization drift risk to API3 and API5 - #146

Open
balaakasam wants to merge 2 commits into
OWASP:developfrom
balaakasam:agentic-stale-oauth-scope-docs
Open

Add agentic stale OAuth scope authorization drift risk to API3 and API5#146
balaakasam wants to merge 2 commits into
OWASP:developfrom
balaakasam:agentic-stale-oauth-scope-docs

Conversation

@balaakasam

Copy link
Copy Markdown

This PR addresses the gap where stale or over-privileged OAuth scopes in agentic systems can bypass function-level authorization.

It adds guidance to:

  • API3: Broken Object Property Level Authorization
  • API5: Broken Function Level Authorization

This introduces a new architectural risk pattern involving autonomous agents retaining stale scopes across task boundaries.

@balaakasam

Copy link
Copy Markdown
Author

Thank you for reviewing. Happy to adjust language or placement to align with project conventions if needed.

@ErezYalon
ErezYalon changed the base branch from master to develop August 25, 2026 06:24
@ErezYalon ErezYalon added the pending community feedback Waiting to be reviewed by the community label Aug 25, 2026
@ErezYalon

Copy link
Copy Markdown
Member

Tagging this as pending community feedback, tied to the discussion on #145. This introduces a new "Agentic System Risk" content pattern, which needs broader input before merging — keeping this open as a candidate for the next version rather than closing it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pending community feedback Waiting to be reviewed by the community

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants