DEV Community

Cover image for API Testing Rule 4/10: Authentication Authorization
Liudas
Liudas

Posted on

API Testing Rule 4/10: Authentication Authorization

A valid token proves identity, not permission.

Testing whether a user can access their own profile is not enough. Repeat the same request with another user’s resource ID and verify that access is denied.

Check different roles, owned and unowned resources, cross-tenant access, read/update/delete operations, and predictable IDs.

Authentication can work perfectly while authorization fails completely.

Rentgen helps discover these issues by testing API behavior beyond the expected authenticated request.

Read the complete white paper:https://qaontime.com/research/the-power-of-ten-rules-for-testing-http-apis.html

Automation Before Automation.

Top comments (0)