I recently caught a security gap in AI-assisted code that's worth sharing because of how easy it was to miss and what it took to actually fix it.
I was using SignalR to push real-time updates to connected clients. AI helped build the implementation, but I wasn't precise enough in my spec: the update ended up being broadcast to all connected clients, not just the relevant one. I missed the .All in my own review:
_hubContext.Clients.All.SendAsync("Status", status);
Once I caught it, I asked the AI assistant for a fix. Its suggestion: filter the messages client-side, in React. I thought about it, and had a feeling this was not correct. Anyone could still see all the raw messages in network traffic, and the filter itself could be bypassed with a couple of clicks in the browser's dev tools (F12). I asked directly, and the assistant agreed: client-side filtering is not access control, it's cosmetic.
I asked if we couldn't better do this in the backend instead. That turned out to be both simpler and bulletproof from a security standpoint: send the message directly to the right client, before it ever reaches anyone else.
await _hubContext.Clients.User(userId).SendAsync("Status", status);
Takeaways
- Without a clear spec, AI can make assumptions you're not aware of. Not all AI assistants ask clarifying questions before filling in the gaps.
- Stay sharp, even when AI does most of the implementation work. I was reviewing every step of this one, and still missed it; which makes me think harder about what review needs to look like as AI agents take on more with less step-by-step involvement.
- The simplest fix isn't always the first one suggested, check what you already have before introducing something new.