Lesson 24 / 25

Secure Code Review

What reviewers look for.

Focus on trust boundaries

Security-focused review concentrates on where untrusted data enters (request parameters, headers, files, webhooks, messages) and where it is used in sensitive sinks (queries, HTML, shell commands, file paths, URLs fetched by the server, deserialisation). Check that every endpoint authenticates and authorises, that secrets are not added to code, that new dependencies are justified, and that errors and logs do not leak data. Small, focused pull requests make careful review possible.

Questions for every pull request

A reviewer's quick guide.

1. What new input does this accept, and is it validated (type, size, format)?
2. Does every new endpoint check authentication AND authorisation for the specific object?
3. Does untrusted data reach SQL, HTML, a shell, a file path or a server-side URL fetch?
4. Are secrets, tokens or personal data logged or returned in errors?
5. Are new dependencies necessary, maintained and pinned?
6. Do failures fail closed, and are multi-step writes transactional?

Pair automated tools with humans

Tools find patterns; humans find logic flaws such as a missing ownership check.

Quick check: Where should secure code review focus most?

  • Variable naming only
  • Code formatting
  • Where untrusted input crosses trust boundaries and reaches sensitive sinks
  • Comment spelling
Answer

Where untrusted input crosses trust boundaries and reaches sensitive sinks — Follow the data.