Nov 2025 - Feb 2026 · Auth / RBAC · Node, Go, Postgres
The auth service's role middleware was a stub an AI tool had left behind. It looked like a guard, logged like a guard, and guarded nothing.
Because the controller read the dashboard's variables instead of the user's role, permission checks were bypassed across a 10+ microservice CHMS. Any session could act as any role.
Tore out the stub and rebuilt the layer against the user service as the single source of truth; routed the service's router in Go so the check sits where the request enters.
Zero privilege escalation paths left open. The auth service finally owns what it claims to own - and every microservice asks it, not the dashboard.