Test cross-tenant access is blocked
Hard120 pts~45 min
- Multi-tenancy
- Broken object-level authorization
Practice app · Acme REST API
A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.
Your starter code already declares BASE_URL — call the API relative to it.
Objective
Prove a user can read their own tenant's invoices but not another tenant's.
Your task
- 1Get a token for the viewer fixture (tenant globex).
- 2GET BASE_URL + "/tenants/globex/invoices" → assert 200.
- 3GET BASE_URL + "/tenants/acme/invoices" with the same token → assert 403 FORBIDDEN.
Acceptance criteria
- Own tenant returns 200
- Other tenant returns 403
- At least 2 assertions pass
Fixtures
- apiKey
- tqa_live_key_123
- basicUser
- admin
- basicPassword
- secret
- username
- qa@target.dev
- password
- Test@123
API testing · API Testing · Authorization & negative testing