Terminology Index
Glossary
2953 terms
N6
O26
Object and Function Authorization Testing
Object and function authorization testing verifies that the server permits each subject to perform only approved actions on approved objects in the correct role, tenant, and workflow state.
It uses synthetic peer and privileged identities across direct, bulk, export, search, file, administrative, and background operations and verifies both the response and durable side effect.
Introduced in: Web Application Penetration Testing
Examples
- Read a peer-owned test object with another user
- Attempt an admin operation from a standard test account
No related terms linked yet.
