Commit to one object-auth test
Commit to adding one concrete cross-object authorization regression test.
Add one cross-object authorization regression test for an API endpoint that accepts a path, query, body, or GraphQL object ID. Choose a real endpoint such as GET /projects/{id}, PATCH /teams/{team_id}, DELETE /documents/{id}, or a GraphQL mutation with an object ID. I will test [actor A] cannot [action] [actor B or tenant B object] on [endpoint]; expected result is [403/404]; the fixture creates [two users/tenants] and swaps [object_id]. In 2 days, confirm whether the denied test exists, failed first, or revealed a missing policy check. A pull request touches an endpoint that takes invoice_id, team_id, document_id, or report_id`. An API bug…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in