Skip to content

Repository files navigation

AuthMap

Authorization coverage mapping for application code.

CISecurityCodeQLLicense: MITRust 1.95+Latest release


AuthMap maps authorization coverage across the routes, handlers, service calls, and data mutations in your application. It answers a foundational appsec question — what protects each endpoint, and the data it touches? — by building a structured, reviewable auth map with typed evidence so missing checks, misplaced controls, and risky drift surface before they ship.

Authorization bugs are often inventory failures before they are coding failures. AuthMap gives you the inventory.

AuthMap's post-v1 capability areas are folded into this single map rather than separate tools: route inventory, policy evidence and explanation, tenant and ownership review, semantic authorization diffs, focused controls review, CI outputs, SARIF, and downstream JSON integrations. See docs/CAPABILITIES.md for workflow examples and limitations.

Quickstart

Install from source:

cargo install --git https://github.com/Ozark-Security-Labs/AuthMap authmap-cli

Prebuilt binaries for Linux, macOS, and Windows are attached to each GitHub Release.

Then bootstrap a config and scan:

authmap init --output authmap.yml
authmap scan . --config authmap.yml --format markdown --output authmap.md
authmap routes . --config authmap.yml --format markdown --output authmap.routes.md

Use it in CI with the GitHub Action:

- uses: actions/checkout@v4
- uses: Ozark-Security-Labs/AuthMap@v0.1.0with:
mode: advisoryoutput: markdown,json

Sample output

A scan of an Express + Prisma service surfaces 15 routes, classifies each by coverage type, and flags routes that need human review:

# AuthMap Report
- Tool: authmap 0.1.0
- Schema: 0.1.0
## Summary
- Mode: advisory
- Routes: 15
- Evidence entries: 23
- Mutations: 4
- Frameworks: express: 15
## Route Inventory
| ID | Method | Path | Middleware | Coverage | Risk |
| ---------- | ------ | --------------------- | ---------------------------------- | ------------------ | --------------- |
| route_0001 | GET | /health | none | unauthenticated | low |
| route_0005 | POST | /api | requireAuth, audit | authn_only | review_required |
| route_0007 | PATCH | /api/:accountId | requireAuth, requirePermission | permission_guarded | review_required |
| route_0009 | DELETE | /api/:accountId | requireAuth, requireAdmin | admin_guarded | review_required |
| route_0014 | GET | /api/tenant/:tenantId | requireAuth, requireTenant | tenant_guarded | low |

The same scan emits JSON for automation, including per-route coverage with linked evidence and reachable mutations:

{
"route_id": "route_0009",
"class": "admin_guarded",
"risk": "review_required",
"rationale": [
"1 strong authorization evidence item(s) support admin_guarded coverage.",
"Sensitive route modifier(s): account_path, linked_mutation, path_param, unsafe_method.",
"Linked data mutation(s) increase review sensitivity."
],
"extensions": {
"authmap.coverage": {
"evidence_ids": ["evidence_0014"],
"mutation_ids": ["mutation_0004"],
"link_ids": ["link_0004"],
"sensitivity_reasons": ["account_path", "linked_mutation", "path_param", "unsafe_method"]
}
}
}

A SARIF report covering the same routes is available for GitHub code scanning.

Supported frameworks

FrameworkLanguage(s)
FastAPIPython
DjangoPython
Django REST FrameworkPython
ExpressNode.js / TypeScript
Next.js (App + Pages)TypeScript / Node.js
tRPCTypeScript
GraphQLPython / TypeScript / Node.js

Plus ORM mutation evidence for SQLAlchemy, Django ORM, and Prisma (with best-effort detection of Sequelize, Mongoose, and TypeORM), linked to the routes that can reach them.

Evidence sources include middleware, decorators, guards, policy objects, service-layer checks, ownership and tenant-isolation patterns, and ORM mutations. See docs/PARSERS_AND_ADAPTERS.md for the adapter contract.

What you get

Typed coverage classification. Each route is placed into one of nine classes — public_declared, unauthenticated, authn_only, role_guarded, permission_guarded, ownership_guarded, tenant_guarded, admin_guarded, unknown_or_dynamic — with a risk label and a machine-readable rationale.

Policy and tenant review. PolicyLens-style policy cases, authmap explain, and the focused authmap tenants report connect route coverage to guard, permission, ownership, tenant, dynamic-policy, linked-mutation, confidence, and reviewer-question context without claiming runtime exploitability.

Drift detection in CI. Capture a baseline JSON document and diff future scans against it. AuthMap reports added or removed routes, evidence changes, coverage downgrades, and newly reachable mutations — with policy knobs to fail builds on specific drift categories.

authmap baseline create . --output authmap.baseline.json
authmap scan . --format json --output authmap.json
authmap diff --base authmap.baseline.json --head authmap.json --format markdown

Rule suggestions.authmap rules suggest is a local, read-only helper that scans for project-specific guard, role, and permission patterns and proposes additions to authmap.yml. It never modifies your config.

Explainable findings.authmap explain <id> resolves any route, evidence, mutation, or link ID against a generated report and prints the supporting context — useful for triage and PR review.

Focused controls review.authmap controls accepts the same inputs as authmap diff and summarizes auth-relevant guard, route guard, permission map, tenant, ownership, admin, audit, policy-helper, and header drift for PR review.

Output formats

FormatUse it for
MarkdownHuman review, PR comments, GitHub Actions job summaries
JSONAutomation and downstream tooling (schema v0.1.0 contract)
SARIFGitHub / GitLab code scanning, advisory alerts

The canonical JSON contract is documented in docs/SCHEMA.md and defined by schemas/authmap.schema.json.

CI integration

Run AuthMap on every pull request and gate enforcement on a baseline diff:

name: AuthMapon:
pull_request:
permissions:
contents: readjobs:
authmap:
runs-on: ubuntu-lateststeps:
- uses: actions/checkout@v4
- uses: Ozark-Security-Labs/AuthMap@v0.1.0with:
mode: enforceoutput: markdown,jsonbaseline: authmap.baseline.jsonfail-on: added_high_risk_route,auth_downgrade,new_linked_mutation

Enforce mode writes the requested reports first, then exits 20 when blocking diagnostics or baseline-drift policy matches are present. SARIF upload is optional and requires security-events: write. See docs/GITHUB_ACTION.md for all inputs, outputs, and permission details.

Exit codes

CodeMeaning
0Success
2CLI usage error
10Target path does not exist or is unreadable
11Enforce-mode target contains no supported source files
12Config file cannot be read, parsed, or validated
13Scan pipeline failed for another reason
14Report rendering or writing failed
20Enforce-mode diagnostic or drift policy failure (report was still written)

Project status

  • v0.1.0 — first public release. Semantic versioning per docs/RELEASES.md.
  • JSON schema — v0.1.0 contract; breaking changes ship via the documented compatibility policy.
  • Rust — MSRV 1.95, edition 2024.
  • Platforms — Linux, macOS, and Windows are tested in CI.

Documentation

DocumentContents
docs/USAGE.mdEnd-to-end CLI usage, output interpretation, defensive-use guidance
docs/CAPABILITIES.mdFolded capability model and post-v1 workflow examples
docs/SCHEMA.mdJSON schema and contract
docs/JSON_CONSUMERS.mdDownstream JSON consumer contract and examples
docs/CONFIGURATION.mdauthmap.yml, custom authorization rules, sensitivity labels
docs/DIAGNOSTICS.mdDiagnostic categories, stable codes, exit behavior
docs/GITHUB_ACTION.mdAll Action inputs, outputs, and permissions
docs/ARCHITECTURE.mdLayered design overview
docs/IMPLEMENTATION_ARCHITECTURE.mdTechnical implementation patterns
docs/PARSERS_AND_ADAPTERS.mdAdding new framework adapters
docs/PRODUCT_BRIEF.mdProduct framing and threat model
docs/ROADMAP.mdFuture direction
docs/RELEASES.mdVersioning, changelog, and compatibility policy
docs/SUPPLY_CHAIN.mdDependency, lockfile, and CI security policy
docs/DATA_HANDLING.mdReport sensitivity and sharing guidance

Security

AuthMap is intended for authorized, defensive analysis of code that you own or are explicitly approved to review. Report vulnerabilities privately via GitHub Security Advisories — see SECURITY.md.

Supply-chain posture:

  • Cargo.lock is committed and reviewed.
  • All GitHub Actions in workflows are pinned to a full commit SHA.
  • CI runs cargo audit, GitHub dependency review, CodeQL, and dependency-determinism checks on every PR.

Details in docs/SUPPLY_CHAIN.md.

Contributing

Design-first contributions are welcome — new framework adapters, evidence detections, documentation, and reviewable detections.

Non-goals

AuthMap will not exploit authorization bugs, attack live systems, or claim vulnerabilities without evidence. It is not a replacement for human security review and does not require running the target application.

License

AuthMap is licensed under the MIT License.

About

Authorization coverage mapping for application routes, handlers, service calls, and data mutations.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages