# OWASP Top 10 Web App Testing Checklist

Authorized use only. Confirm written scope, rate limits, test accounts, and data
handling rules before testing. Prefer staging unless production testing is
explicitly approved.

## A01 Broken Access Control
- Verify direct object references require authorization checks.
- Test role transitions with least-privilege accounts.
- Confirm admin endpoints reject unauthenticated and low-privilege users.
- Check CORS allowlist behavior.

## A02 Cryptographic Failures
- Confirm TLS 1.2+ and strong certificates.
- Verify sensitive cookies use `Secure`, `HttpOnly`, and `SameSite`.
- Confirm secrets and tokens are never logged or returned in API responses.

## A03 Injection
- Test representative parameters with safe non-destructive payloads.
- Validate parameterized queries or ORM bind variables in code review.
- Confirm server-side validation for JSON, form, header, and path inputs.

## A04 Insecure Design
- Review threat model for payment, authentication, and tenant boundaries.
- Check business logic abuse cases such as replay, quantity manipulation, and state skipping.

## A05 Security Misconfiguration
- Review security headers, error pages, debug modes, default credentials, and open storage buckets.
- Confirm framework and dependency security recommendations are applied.

## A06 Vulnerable and Outdated Components
- Run dependency audit tooling and verify reachable vulnerable code paths.
- Document compensating controls when upgrades cannot be immediate.

## A07 Identification and Authentication Failures
- Confirm MFA flows, password policy, lockout/rate limiting, and session invalidation.
- Check password reset tokens for expiry, single use, and unpredictability.

## A08 Software and Data Integrity Failures
- Verify CI/CD permissions, artifact signing, dependency pinning, and webhook validation.

## A09 Security Logging and Monitoring Failures
- Confirm authentication failures, privilege changes, and sensitive actions create useful audit logs.
- Verify logs avoid secrets and personal data beyond approved retention.

## A10 Server-Side Request Forgery
- Test URL-fetching features against approved canary hosts only.
- Confirm egress allowlists, metadata endpoint blocks, and DNS rebinding defenses.

## Evidence Format
| Finding | Endpoint | Account Role | Evidence | Impact | Recommendation |
|---|---|---|---|---|---|
