API testing

Test cross-tenant access is blocked

Hard120 pts~45 min
  • Multi-tenancy
  • Broken object-level authorization
Practice app · Acme REST API

A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.

BASE_URL
/api/practice
Console app
/lab/api-testing-test-cross-tenant-access-is-blocked

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Prove a user can read their own tenant's invoices but not another tenant's.

Your task

  1. 1Get a token for the viewer fixture (tenant globex).
  2. 2GET BASE_URL + "/tenants/globex/invoices" → assert 200.
  3. 3GET BASE_URL + "/tenants/acme/invoices" with the same token → assert 403 FORBIDDEN.

Acceptance criteria

  • Own tenant returns 200
  • Other tenant returns 403
  • At least 2 assertions pass

Fixtures

apiKey
tqa_live_key_123
basicUser
admin
basicPassword
secret
username
qa@target.dev
password
Test@123

API testing · API Testing · Authorization & negative testing