Security tests should exercise abuse cases

Testing that the feature works is not testing that it cannot be misused.

The test suite proves the happy path and the obvious errors. The abuse cases, negative quantities, replayed requests, another user's identifier, missing authorisation, are exactly what nobody writes tests for, and exactly what somebody will try. Turning them into tests means a regression gets caught rather than rediscovered.

More on Secure development