Knowledgebase

Testing Permissions and Multi-Tenancy Print

  • softwaretestingqa, software, permissions, database, guide, howto, solution, zillionkinghost
  • 0

Verifying isolation.

WHAT TO TEST FOR EVERY ROLE

Every function they should access Every function they should not Every record they should see Every record they should not

WHAT TO BUILD

A matrix of roles against protected functions.

WHY A MATRIX

It is large, and omissions are invisible without one.

WHAT TO AUTOMATE

That matrix, since it must be rechecked on every change.

WHAT TO TEST ABOUT TENANCY

That one customer cannot see another's data, through any route.

WHAT ROUTES TO CHECK

Direct record access by identifier Lists and searches Reports and exports Interfaces Notifications

WHY EXPORTS SPECIFICALLY

They frequently bypass the filtering applied elsewhere.

WHAT TO TEST ABOUT ROLE CHANGES

That removing a role removes access immediately That existing sessions are affected

WHY SESSIONS MATTER

Access removed in the database but not in the session persists.

WHAT TO TEST ABOUT SHARED RESOURCES

Identifiers that could collide between tenants.

WHAT TO VERIFY AT THE DATA LAYER

That scoping is enforced there, not only in the interface.

WHY

Any route bypassing the interface then remains safe.

WHAT TO TREAT ANY CROSSING AS

A critical defect.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot