Intent-Code Divergence
Medium
- Confidence
- 94% confidence
- Finding
- The test encodes insecure authorization behavior: despite the description saying display-name allowlists are ignored, it expects approval authorization to succeed when only a display name is configured in allowFrom. In an approval/execution path, trusting mutable, non-unique display names can let an attacker impersonate an approver and gain unauthorized approval for sensitive actions.
