AntiPattern
Auth & Crypto Misuse Boundaries
auth-crypto-boundary-misuse
Authorization and encryption primitives get misused across trust boundaries—JWT validation is mixed with signing, AES-CBC lacks authentication, HMAC/JWKS assumptions are unclear, and secrets persist longer than needed—causing forged tokens, tampered ciphertext, and key leakage.