Skip to main content

Security Smoke Tests

IDTest CaseTypePriorityExpected ResultEvidence RequiredStatus
TC-SEC-001Unauthenticated protected page accessSecurityCriticalUser is redirected or deniedScreenshotNot Run
TC-SEC-002Unauthenticated protected API accessSecurityCriticalAPI returns unauthorizedAPI responseNot Run
TC-SEC-003Role escalation attemptSecurityCriticalAccess deniedAPI response or screenshotNot Run
TC-SEC-004Cross-tenant ID tampering attemptSecurityCriticalAccess deniedAPI request/responseNot Run
TC-SEC-005Sensitive file upload validation where applicableSecurityHighInvalid or unsafe upload rejectedAPI/UI evidenceNot Run
TC-SEC-006Secrets are not exposed in public documentationSecurityHighNo secrets foundReview evidenceNot Run