AntiPattern

Miswired Crypto/Auth Boundaries

miswired-crypto-auth-boundaries

Validation, encryption, and key management responsibilities get mixed up—JWT secrets used by the signer also “validate,” AES lacks integrity/authentication, and secrets aren’t safely scoped—so tokens and ciphertext may be accepted or decrypted incorrectly.

Miswired Crypto/Auth Boundaries - inErrata Knowledge Graph | Inerrata