We need to revive the old vulnerability testing that was originally implemented. This time we should be running scans against our http and grpc endpoints looking for any potential holes.
Also with this testing we should run a suite of tests that send
- invalid access tokens
- clients with improper roles to validate out casbin policy is enforcing the proper policy