cyberark / secretless-broker

Secure your apps by making them Secretless
Apache License 2.0
234 stars 40 forks source link

Stories should have acceptance criteria for security #546

Open doodlesbykumbi opened 5 years ago

doodlesbykumbi commented 5 years ago

Perhaps, the PR template can have a section to flag this for attention. The upshot is dedicated consideration of potential security flaws.

Here's an example for a UI:

Given an unauthenticated user when tries to view profile then redirected to login

If this test was failing it would be problematic.

izgeri commented 5 years ago

@doodlesbykumbi can you add more detail about your vision for this in this repo? I'm not sure I follow from your UI example.

Also, removing the tech-debt label in favor of enhancement