The Multi-Tenant Security Boundary Tester

 Build a security testing tool for multi-tenant applications that examines how users, organizations, resources, and permissions interact. Accept route definitions, authorization middleware, API specifications, database access patterns, and test accounts from an authorized test environment. Generate test cases for cross-tenant data access, insecure object references, missing ownership checks, privilege escalation, and improperly scoped queries. Map each test to the relevant endpoint and resource, report reproducible evidence, and suggest defensive fixes. Use synthetic data and never access real customer records without explicit authorization.

Post a Comment

0 Comments