The 403 bypass scanner could mistake a single-page application's public fallback response for protected content. Stopping at that first apparent success could also hide a later real bypass.
The change
Compare successful payload responses with successful responses from the site root and a random sibling path. Ignore identical public fallback bodies and continue testing remaining path and header payloads. Update the scanner help and changelog.
Submitted upstream with 33 focused tests, 346 add-on tests and six installed ZAP comparison runs passing locally. Awaiting maintainer review; not merged or released.
Verification & review
Five regression cases failed against the unchanged scanner. The patched rule passed all 33 focused cases and all 346 beta add-on tests, plus style checks and packaging. Six asserted runs compared released and patched add-ons against synthetic loopback fixtures: the patched scanner ignored the plain SPA fallback and identified the real path and header bypasses. CLA and Checkmarx checks pass; upstream Java CI and CodeQL await maintainer approval.
Exact body matching leaves dynamically changing fallback pages as a limitation. The rule adds two control requests per scanned 403 endpoint. Status checked on 3 October 2026. AI assistance was used for investigation, implementation and validation.
Contribution status checked on 3 October 2026. Submitted work is labelled separately from merged contributions. Benchmarks describe the stated workload, rather than whole-product performance.
The next chapter
Good work starts with a conversation.
Engineering opportunities, thoughtful teams, and useful problems in software, AI and cybersecurity.