Tell me what's brokenWhat's broken?

Shofar.ai - the RBAC that wasn't there

Nov 2025 - Feb 2026 · Auth / RBAC · Node, Go, Postgres

00 · found

Permission checks existed in name only.

The auth service's role middleware was a stub an AI tool had left behind. It looked like a guard, logged like a guard, and guarded nothing.

controller → dashboard variables (not the user's role)
01 · blast radius

Bypassed platform-wide.

Because the controller read the dashboard's variables instead of the user's role, permission checks were bypassed across a 10+ microservice CHMS. Any session could act as any role.

02 · rebuild

User service = source of truth.

Tore out the stub and rebuilt the layer against the user service as the single source of truth; routed the service's router in Go so the check sits where the request enters.

controller → user service → role → enforced
10+ microservices secured1 source of truth0 checks left unenforced
03 · verified

Role checks, enforced.

Zero privilege escalation paths left open. The auth service finally owns what it claims to own - and every microservice asks it, not the dashboard.