Security tests should exercise abuse cases
Testing that the feature works is not testing that it cannot be misused.
The test suite proves the happy path and the obvious errors. The abuse cases, negative quantities, replayed requests, another user's identifier, missing authorisation, are exactly what nobody writes tests for, and exactly what somebody will try. Turning them into tests means a regression gets caught rather than rediscovered.
More on Secure development
- Threat modelling asks how a design can fail before code existsBreak it on paper first
- Input validation defines what the application acceptsOne shape fits
- Security requirements are product requirementsThey go on the same sheet
- Code review and automated scanning see different risksThe magnet and the eye
- Feature flags can become security statesSomebody left it up
- Error handling should fail predictablyBreak the same way every time
