rized function is requested.
If you have only one user-level account with which to access the application
(or none at all), then additional work needs to be done to test the effectiveness
of access controls. In fact, to perform a fully comprehensive test, further work
needs to be done in any case, because poorly protected functionality may exist
that is not explicitly linked from the interface of any application user — for
example, old functionality that has not yet been removed, or new functionality
that has been deployed but has not yet been published to users.
Do'stlaringiz bilan baham: |