Authentication & Authorization (AAX)
Prasad can bypass the centralized authentication and authorization controls since they are not being used comprehensively on all interactions
Scenario: Prasad can bypass the centralized authentication and authorization controls since they are not being used comprehensively on all interactions
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
OWASP MASVS: AUTH-1
OWASP MASTG: TEST-0017,TEST-0064
SAFECode: 8,10,11
Attacks
No attacks registered!