Intent-Code Divergence
Medium
- Confidence
- 90% confidence
- Finding
- The guide explicitly says `secret_name` is a sensitive field that should not be exposed, but the update model still allows clients to submit and modify it. In a real application, this creates an authorization and data-integrity risk because consumers may assume the field is protected while the API permits direct tampering.
