One perfect half is themost dangerous result there is.
Every request to your app has to get past two things: your server deciding instead of the browser, and your server checking who is asking. Either one alone is a formality — a server-side decision that never asks whose record this is still lets the request through. Three RedHub tools that grade both halves and the surprise you'd otherwise walk into, $38 less than buying them separately.
A door needs both halves, and they guard different things.
Fix the browser line and it comes back clean — every decision moved to the server, nothing trusting what the browser sends. That kit reads LINE HOLDS, and it's correct. But every signed-in person can still open every record, because the other half was never the browser's job. Your server decides, correctly, on the server — and then hands over whatever record id it was given, to whoever asked.
The clean half is the one you'll remember. So this bundle names it explicitly: when one half is perfect and the other is absent, the rollup says so in words, because a green verdict you half-remember is worse than no verdict at all.
Three tools. One question about your front door.
Each tool is the same full product sold on its own page — nothing trimmed for the bundle. Click any card to see the individual product page.
The Browser Line Read-Off
Grades whether your app's decisions are actually made on your server, or taken from the browser.
View productLogged-In Is Not Allowed
Grades whether your server checks that this record belongs to the person asking, not just that they're signed in.
View productCan You Explain Your Own App?
The line's map — tells you whether a finding is a surprise, and names the one thing to open first.
View productBought separately: $177 · Bundle: $139 — one of the three is effectively free.
AND, not worst-of — because neither half counts alone.
Where
The Browser Line Read-Off grades whether each decision your app makes is actually made on your server, or handed to it by the browser. A clean read here means one half of the door is solid.
Who
Logged-In Is Not Allowed grades whether your server checks that this record belongs to the person asking — not just that somebody is signed in. That's the other half, and it guards something different.
Compose, don't average
The rollup reads both halves with AND, not worst-of. A perfect half never raises the door on its own — and where one half is flawless and the other absent, the rollup names the strong half out loud, because that's the reading you'd carry away.
Verdicts read DOOR HOLDS / ONE HALF OF A DOOR / NO DOOR — anything unsupplied reads NOT RUN and blocks the top verdict. The hub's account of what you could explain is reported, never scored: it answers whether a finding is a surprise, not how bad it is, and a claim that turned out right is never held against you.
Three rules the rollup won't bend for you.
Every tool in this stack holds the same RedHub standard — it reads back exactly what you tell it, and it refuses to let one good half stand in for a door.
A perfect half doesn't raise the door
The top verdict needs both halves at full strength. LINE HOLDS with ANYONE CAN WALK IN still reads NO DOOR — and so does the mirror image. Neither half is privileged; the rollup is symmetric.
The false comfort gets named, not just outvoted
Where one half is perfect and the other is at its worst, the rollup prints the strong half by name and says it isn't protecting anything on its own. It only fires on that exact combination — a merely-partial half is a different situation.
Your own account is reported, never scored
Whether you said you could explain a finding is counted and printed — it moves nothing. A claim that turned out right is never held against you either; it answers whether this is a surprise, not how bad it is.
For the person who fixed one half and stopped.
You moved decisions to the server
And haven't looked at who's allowed to do what once they're there. This bundle checks the half you didn't finish.
You have route-level permission checks
But you're not sure the decisions that matter actually reach them before the response goes out. The rollup won't let you assume.
Somebody told you it was fine because it checks login
And it didn't sit right. Being signed in is a membership test; being allowed is a comparison between a record and a person — this bundle grades the difference.
All three kits read back what you tell them. They connect to nothing, send no requests, and see no part of your project. None of this grades a person, none of it is a penetration test, and none of it is legal advice.
One purchase. Three tools. Save $38.
- The Browser Line Read-Off$59
- Logged-In Is Not Allowed$59
- Can You Explain Your Own App?$59
- Bought separately$177
Already own one of these? Each tool also stands alone — buy the bundle only if two or more fit how you work. See all RedHub bundles for the rest of the Past the Prototype line.
Answers before you ask.
Because a door needs both halves and they guard different things. A decision made on your server that never asks whose record this is still lets the request through — it just routes it through your code on the way. And a flawless ownership check on a decision the browser makes is a lock on a door somebody can walk around.
Neither, and the rollup is symmetric about it. LINE HOLDS with ANYONE CAN WALK IN reads NO DOOR, and so does the mirror image. If a rollup privileged one half, it would be encouraging you to finish that one and stop, which is the exact situation this exists to catch.
Where one half is perfect and the other is at its worst, the rollup names the strong half explicitly and says it is not protecting anything on its own. That green reading is the one you will carry around, and it is the reason you will not come back to this. It does not fire when the other half is merely partial — that is a different situation.
Because it answers a different question. The two halves tell you how bad it is; your own account tells you whether it is going to be a surprise. Those need different responses, and the rollup keeps them apart on purpose — a claim that turned out right is never held against you.
You can start with one, and the rollup will read it. Anything missing reads NOT RUN, and it will not give you the top verdict while a half is absent — one clean half of two is not a door, and the sheet says so rather than implying otherwise.
No. All three are spreadsheets you fill in from your own code and screens. Nothing sends a request, nothing probes a route, and nothing is uploaded. It is a read-off, not a penetration test.
Find out whether you have
a door, or half of one.
Two halves of one door, plus the line's map. $38 less than buying them separately.
Sold by RedHub AI LLC · Secured by Stripe · redhub.ai