A valid token proves identity, not permission.
Testing whether a user can access their own profile is not enough. Repeat the same request with another user’s resource ID and verify that access is denied.
Check different roles, owned and unowned resources, cross-tenant access, read/update/delete operations, and predictable IDs.
Authentication can work perfectly while authorization fails completely.
Rentgen helps discover these issues by testing API behavior beyond the expected authenticated request.
Read the complete white paper:https://qaontime.com/research/the-power-of-ten-rules-for-testing-http-apis.html
Automation Before Automation.

Top comments (0)