I’ll map the Meridian staging portal, establish Nina Patel’s and Owen Price’s approved accounts, and inspect authentication and tenant boundaries within staging.meridian-commerce.example.
The application exposes account, invoice, team, and authentication routes. Nina Patel’s Meridian account and Owen Price’s Harbor & Pine account are available for validation.
/auth/*Mapped/api/invoices/*Finding validated/api/team/*Finding validatedMay I request Harbor & Pine Retail’s designated invoice while signed in as Nina Patel at Meridian Commerce? I’ll keep the request read-only.
Read-only request- Why this check?
- Confirm whether the API enforces invoice ownership.
- Impact
- No data will be modified. Only the two approved test accounts are involved.
Nina Patel’s Meridian Commerce session can read Harbor & Pine Retail’s invoice. I confirmed the ownership mismatch without modifying either record.
May I create an administrator invitation in the isolated test account, then remove it after checking the assigned permissions?
Create test invite- Why this check?
- Confirm whether a member can assign administrator permissions.
- Impact
- One invitation will be created in the test account and removed after validation.
The member account can create an administrator invitation. The test invite was removed after verification.
The signed-out test session is still accepted by the profile endpoint.
The reset endpoint correctly hides account existence, but five bounded requests were accepted without an account cooldown.
Testing is complete. I validated four issues and attached reproducible evidence and recommended fixes. Test artifacts were cleaned up; no real customer records were accessed.