reviewing-security-architecture

작성자: bitwarden

이 스킬은 사용자가 "보안 아키텍처 검토", "인증 패턴 확인", "신뢰 경계 평가", "검토…"를 요청할 때 사용해야 합니다.

npx skills add https://github.com/bitwarden/ai-plugins --skill reviewing-security-architecture

Authentication Architecture

Token Handling

Review these aspects of token-based authentication:

AspectSecure PatternAnti-Pattern
IssuanceShort-lived tokens with refresh mechanismLong-lived tokens that never expire
ValidationValidate signature, issuer, audience, and expiry on every requestValidate only the signature, or skip validation for "internal" calls
Storage (server)Stateless JWT or server-side session storeToken stored in querystring or URL
Storage (client)HttpOnly Secure cookies or secure platform storagelocalStorage, sessionStorage, or cookies without HttpOnly/Secure flags
RefreshRefresh token rotation (old refresh token invalidated on use)Reusable refresh tokens with no rotation
RevocationToken blocklist or short expiry + refresh rotationNo revocation mechanism for compromised tokens

Session Management

  • Server-side sessions should have absolute timeouts (maximum session duration) and idle timeouts
  • Session identifiers must be cryptographically random and sufficiently long (128+ bits of entropy)
  • Regenerate session ID after authentication state changes (login, privilege escalation)
  • Bind sessions to client properties where possible (IP range, user agent) for anomaly detection

Credential Storage

  • Passwords must be hashed with a modern KDF: Argon2id (preferred), bcrypt, or PBKDF2 with high work factor and a unique salt
  • Never use raw cryptographic hash functions alone for password hashing (too fast, no salt by default)
  • Salts should be unique per credential to prevent rainbow-tables from accelerating brute-force attacks

Authorization Patterns

Role-Based Access Control (RBAC)

// CORRECT — explicit role check at the API layer
[Authorize(Roles = "Admin")]
public async Task<IActionResult> DeleteUser(Guid userId)

// WRONG — checking role in business logic with string comparison
if (currentUser.Role == "admin") // Fragile, case-sensitive, easy to bypass

Object-Level Authorization

// WRONG — trusts the userId from the route, no ownership check
public async Task<Cipher> GetCipher(Guid cipherId) {
    return await _cipherRepository.GetByIdAsync(cipherId);
}

// CORRECT — verify the requesting user owns the resource
public async Task<Cipher> GetCipher(Guid cipherId) {
    var cipher = await _cipherRepository.GetByIdAsync(cipherId);
    if (cipher.UserId != _currentContext.UserId)
        throw new NotFoundException();
    return cipher;
}

Authorization Principles

  • Check at every layer. API controller, service layer, and data access should all enforce authorization. Don't rely on a single checkpoint.
  • Least privilege. Grant the minimum permissions needed. Default to deny.
  • Fail closed. If an authorization check fails or throws an exception, deny access. Never fail open.
  • Don't trust client-side authorization. UI visibility controls are UX, not security. Always enforce server-side.

Data Protection

Encryption at Rest

  • All sensitive data must be encrypted at rest using AES-256 or equivalent
  • Cryptographic keys MUST NEVER be stored directly accessible in a database, without being wrapped by another key
  • Use envelope encryption: data encrypted with a data encryption key (DEK), DEK encrypted with a key encryption key (KEK) in a key management system
  • Bitwarden's end-to-end encryption ensures vault data is encrypted before leaving the client

Encryption in Transit

  • TLS 1.2 minimum, TLS 1.3 preferred
  • Disable older protocols (SSL 3.0, TLS 1.0, TLS 1.1)
  • Use strong cipher suites (ECDHE for key exchange, AES-GCM for encryption)
  • Certificate pinning for mobile apps where appropriate
  • Internal service-to-service communication should also use TLS

Data Classification

When reviewing architecture, identify data by classification:

ClassificationExamplesRequired Protection
CriticalEncryption keys, master passwords, vault dataEnd-to-end encryption, HSM key storage
ConfidentialPII, email addresses, billing infoEncryption at rest + in transit, access logging
InternalOrganizational settings, feature flagsEncryption in transit, role-based access
PublicMarketing content, public API docsIntegrity protection

Trust Boundaries

A trust boundary exists wherever data crosses between components with different levels of trust. Every crossing must be validated.

Common Trust Boundaries

Client ←→ API Gateway         (user-controlled → server-controlled)
API Gateway ←→ Backend Service (internet-facing → internal)
Backend Service ←→ Database    (application → data store)
Service ←→ External API        (internal → third-party)
Browser ←→ Browser Extension   (page context → extension context)
Main Thread ←→ Web Worker      (different execution contexts)

Validation at Trust Boundaries

At each boundary crossing:

  1. Validate all input — type, format, range, length. Don't trust upstream validation.
  2. Authenticate the caller — verify identity before processing requests.
  3. Authorize the action — verify the caller has permission for this specific operation.
  4. Sanitize output — encode/escape data appropriate to the destination context.
  5. Log the crossing — security-relevant boundary crossings should be auditable.

Zero-Trust Principles

  • Don't trust internal network location as a proxy for authentication
  • Every service-to-service call should be authenticated and authorized
  • Assume the network is compromised — encrypt all internal communication
  • Validate data from internal services just as rigorously as external input

Architecture Decision Alignment

Before evaluating a design, check Bitwarden's Architecture Decision Records for existing decisions relevant to the components under review — see ${CLAUDE_PLUGIN_ROOT}/references/adr-alignment.md for the ground rules (conflict = finding, undocumented significant decision = gap, verify status before citing). Applied to an architecture review specifically:

  • Cite it, don't just flag it. When a design conflicts with an accepted ADR, name the ADR and state whether the implementation should change or the deviation needs its own ADR justifying the exception.
  • Watch for these gap triggers. New trust boundaries, new auth patterns, new data stores, or other consequential choices with no corresponding ADR are exactly the kind of significant decision that should be flagged so it gets recorded, not just implemented.

Reference Material

For detailed lookup tables and code examples, consult:

  • references/crypto-algorithms.md — Algorithm selection table (recommended vs. deprecated) and common crypto anti-pattern code examples
  • references/architectural-anti-patterns.md — Common security architecture anti-patterns (implicit trust, single points of failure, insecure defaults, monolithic auth) with fixes

Connection to Threat Modeling

Architecture security review directly feeds into the threat modeling process:

  • Trust boundary identification informs where to draw boundaries in data flow diagrams
  • Architectural weaknesses become threats in the threat catalog
  • Security properties (auth, encryption, access control) map to security goals in security definitions
  • Anti-patterns found become candidates for Bitwarden's engagement model Phase 1 initial security assessment

When conducting architecture review, consider whether the findings warrant engaging the AppSec team (#team-eng-appsec) for a full threat modeling session.

bitwarden의 다른 스킬

figma-to-angular
bitwarden
이 스킬은 Figma 디자인 스펙을 Bitwarden Clients 모노레포 내에서 Storybook 스토리와 함께 완전히 구현된 Angular 컴포넌트로 변환합니다. 출력물은 모든 코드베이스 규칙을 따르면서 시각적으로 디자인과 일치해야 합니다.
force-multiplier
bitwarden
하나의 의도를 여러 대상에 동시에 적용합니다 — Bitwarden 생태계 전반의 저장소 플릿, 또는 모노레포 내 많은 프로젝트 — N개의 일관된 작업으로, …
analyzing-git-sessions
bitwarden
특정 기간이나 커밋 범위 내의 Git 커밋과 변경 사항을 분석하여 코드 리뷰, 회고, 작업 로그 또는 세션을 위한 구조화된 요약을 제공합니다.
coordinating-cross-team-breakdown
bitwarden
크로스 팀 리뷰 및 Bitwarden 기술 분석에 대한 승인을 조정합니다. 영향을 받는 팀을 식별하고, 파트 3 승인 테이블을 작성하며, 후속 조치를 진행할 때 사용하세요.
assessing-jira-issue-relevance
bitwarden
사용자가 개별 Jira 이슈 키를 제공하고 그것이 여전히 관련이 있는지, 여전히 적용 가능한지, 여전히 보류 중인지, 여전히 버그인지, 수정되었는지, 또는 …인지 물을 때 사용합니다.
assessing-test-coverage
bitwarden
특정 변경(PR, Jira 키, Tech Breakdown 문서, Testmo CSV, 변경된 경로 또는 명명된 항목)에 대해 이미 존재하는 테스트 커버리지를 파악할 때 사용합니다.
retrospecting
bitwarden
Claude Code 세션에 대한 포괄적인 분석을 수행하며, git 히스토리, 대화 로그, 코드 변경 사항을 검토하고 사용자 피드백을 수집하여 생성합니다…
reviewing-incremental-changes
bitwarden
이미 코멘트가 달린 PR을 재검토하거나 초기 리뷰 후 개발자의 변경 사항에 응답할 때 이 스킬을 사용하세요. PR 스레드가 존재하거나...