Firebase functions flawed custom claims authorization logic
Identifies functions that read custom claims but have flawed logic for checking their presence or value before granting access to sensitive operations. This can lead to unauthorized access if a claim is missing or has an unexpected value.