Developer Builds Tool to Detect Lingering Access After Permissions Are Revoked
A developer created an open-source testing tool called Parallax, built for the All Things Agentic Hackathon, that simultaneously opens multiple isolated browser sessions to compare application behaviour across different user roles, locales, themes, and viewport sizes. The tool addresses a security blind spot: while companies log when access is revoked, no standard automated tool measures how long a previously authenticated session continues to function after removal. An already-open browser tab can retain loaded data, active WebSockets, and cached membership status for an unmeasured window of time even after an admin removes a user. OWASP's ASVS V3 standard requires all active sessions to be invalidated upon account disablement, but its own testing guide only describes manual verification methods. Microsoft's continuous-access documentation acknowledges propagation delays of up to 15 minutes, highlighting that this gap remains largely unaddressed by existing tooling.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in