2416 lines
93 KiB
JSON
2416 lines
93 KiB
JSON
[
|
|
{
|
|
"sourceId": "CONS-001",
|
|
"variantId": "V25-CONS-001",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "Firm Admin",
|
|
"scenario": "Consultant list loads for Firm Admin",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-001 Consultant list loads for Firm Admin",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-002",
|
|
"variantId": "V25-CONS-002",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "Consultant",
|
|
"scenario": "Consultant detail page loads",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-002 Consultant detail page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-003",
|
|
"variantId": "V25-CONS-003",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "Consultant",
|
|
"scenario": "Consultant edit form loads",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-003 Consultant edit form loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-004",
|
|
"variantId": "V25-CONS-004",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "Consultant",
|
|
"scenario": "Consultant links page loads",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-004 Consultant links page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-005",
|
|
"variantId": "V25-CONS-005",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "All roles",
|
|
"scenario": "Conversion requests list loads",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-005 Conversion requests list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-006",
|
|
"variantId": "V25-CONS-006",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "All roles",
|
|
"scenario": "Conversion request detail loads",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-006 Conversion request detail loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-007",
|
|
"variantId": "V25-CONS-007",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "All roles",
|
|
"scenario": "Conversion request review CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-007 Conversion request review CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-008",
|
|
"variantId": "V25-CONS-008",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "All roles",
|
|
"scenario": "Service requests list loads",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-008 Service requests list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-009",
|
|
"variantId": "V25-CONS-009",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "All roles",
|
|
"scenario": "Service request detail loads",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-009 Service request detail loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-010",
|
|
"variantId": "V25-CONS-010",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "All roles",
|
|
"scenario": "Service request status update CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-010 Service request status update CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-011",
|
|
"variantId": "V25-CONS-011",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "Staff",
|
|
"scenario": "Staff cannot access consultant list",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-011 Staff cannot access consultant list",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-012",
|
|
"variantId": "V25-CONS-012",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "Client",
|
|
"scenario": "Client cannot access consultant detail",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-012 Client cannot access consultant detail",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-013",
|
|
"variantId": "V25-CONS-013",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "Consultant",
|
|
"scenario": "Non-existent consultant ID returns safe response",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-013 Non-existent consultant ID returns safe response",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CONS-014",
|
|
"variantId": "V25-CONS-014",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Consultants",
|
|
"role": "Consultant",
|
|
"scenario": "Consultant self-service dashboard loads",
|
|
"steps": "Execute Playwright v2.5 module test: CONS-014 Consultant self-service dashboard loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-001",
|
|
"variantId": "V25-DOC-STOR-001",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "Firm Admin",
|
|
"scenario": "Branch storage dashboard loads for Firm Admin",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-001 Branch storage dashboard loads for Firm Admin",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-002",
|
|
"variantId": "V25-DOC-STOR-002",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "All roles",
|
|
"scenario": "Permanent document vault list loads",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-002 Permanent document vault list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-003",
|
|
"variantId": "V25-DOC-STOR-003",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "Client",
|
|
"scenario": "Permanent vault for specific client loads",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-003 Permanent vault for specific client loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-004",
|
|
"variantId": "V25-DOC-STOR-004",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "All roles",
|
|
"scenario": "Permanent vault upload CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-004 Permanent vault upload CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-005",
|
|
"variantId": "V25-DOC-STOR-005",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "All roles",
|
|
"scenario": "Permanent document download requires auth",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-005 Permanent document download requires auth",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-006",
|
|
"variantId": "V25-DOC-STOR-006",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "System Admin",
|
|
"scenario": "Storage jobs list loads for System Admin",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-006 Storage jobs list loads for System Admin",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-007",
|
|
"variantId": "V25-DOC-STOR-007",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "System Admin",
|
|
"scenario": "Storage nodes list loads for System Admin",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-007 Storage nodes list loads for System Admin",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-008",
|
|
"variantId": "V25-DOC-STOR-008",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "All roles",
|
|
"scenario": "Download requests list loads",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-008 Download requests list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-009",
|
|
"variantId": "V25-DOC-STOR-009",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "All roles",
|
|
"scenario": "Storage agent jobs endpoint requires auth",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-009 Storage agent jobs endpoint requires auth",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-010",
|
|
"variantId": "V25-DOC-STOR-010",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "All roles",
|
|
"scenario": "Storage agent download-requests endpoint requires auth",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-010 Storage agent download-requests endpoint requires auth",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-011",
|
|
"variantId": "V25-DOC-STOR-011",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "All roles",
|
|
"scenario": "Storage node toggle CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-011 Storage node toggle CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-012",
|
|
"variantId": "V25-DOC-STOR-012",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "Staff",
|
|
"scenario": "Staff cannot access branch storage dashboard",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-012 Staff cannot access branch storage dashboard",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-013",
|
|
"variantId": "V25-DOC-STOR-013",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "Client",
|
|
"scenario": "Client cannot access permanent vault admin",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-013 Client cannot access permanent vault admin",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-014",
|
|
"variantId": "V25-DOC-STOR-014",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "All roles",
|
|
"scenario": "Permanent document delete CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-014 Permanent document delete CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-015",
|
|
"variantId": "V25-DOC-STOR-015",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "All roles",
|
|
"scenario": "Non-existent permanent document download is handled safely",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-015 Non-existent permanent document download is handled safely",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "DOC-STOR-016",
|
|
"variantId": "V25-DOC-STOR-016",
|
|
"sheet": "UAT_Consultants_Documents_v2_5",
|
|
"module": "Documents",
|
|
"role": "All roles",
|
|
"scenario": "Storage agent agent-package download requires node auth",
|
|
"steps": "Execute Playwright v2.5 module test: DOC-STOR-016 Storage agent agent-package download requires node auth",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "UAT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-HR-001",
|
|
"variantId": "V25-EMP-HR-001",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - HR Admin",
|
|
"role": "Firm Admin",
|
|
"scenario": "HR dashboard loads without error for Firm Admin",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-HR-001 HR dashboard loads without error for Firm Admin",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-HR-002",
|
|
"variantId": "V25-EMP-HR-002",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - HR Admin",
|
|
"role": "Firm Admin",
|
|
"scenario": "Employee list loads for Firm Admin",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-HR-002 Employee list loads for Firm Admin",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-HR-003",
|
|
"variantId": "V25-EMP-HR-003",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - HR Admin",
|
|
"role": "All roles",
|
|
"scenario": "Employee list search does not crash",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-HR-003 Employee list search does not crash",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-HR-004",
|
|
"variantId": "V25-EMP-HR-004",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - HR Admin",
|
|
"role": "All roles",
|
|
"scenario": "Employee create form loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-HR-004 Employee create form loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-HR-005",
|
|
"variantId": "V25-EMP-HR-005",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - HR Admin",
|
|
"role": "All roles",
|
|
"scenario": "Employee create with blank form shows validation, not 500",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-HR-005 Employee create with blank form shows validation, not 500",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "UAT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-HR-006",
|
|
"variantId": "V25-EMP-HR-006",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - HR Admin",
|
|
"role": "All roles",
|
|
"scenario": "Employee detail page loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-HR-006 Employee detail page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-HR-007",
|
|
"variantId": "V25-EMP-HR-007",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - HR Admin",
|
|
"role": "All roles",
|
|
"scenario": "Employee edit form loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-HR-007 Employee edit form loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ATT-001",
|
|
"variantId": "V25-EMP-ATT-001",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Attendance",
|
|
"role": "All roles",
|
|
"scenario": "HR attendance list loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ATT-001 HR attendance list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ATT-002",
|
|
"variantId": "V25-EMP-ATT-002",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Attendance",
|
|
"role": "All roles",
|
|
"scenario": "HR attendance list with filters does not crash",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ATT-002 HR attendance list with filters does not crash",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ATT-003",
|
|
"variantId": "V25-EMP-ATT-003",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Attendance",
|
|
"role": "All roles",
|
|
"scenario": "Manual attendance CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ATT-003 Manual attendance CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ATT-004",
|
|
"variantId": "V25-EMP-ATT-004",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Attendance",
|
|
"role": "All roles",
|
|
"scenario": "Attendance review CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ATT-004 Attendance review CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-LEAVE-001",
|
|
"variantId": "V25-EMP-LEAVE-001",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Leave",
|
|
"role": "All roles",
|
|
"scenario": "Leave types list loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-LEAVE-001 Leave types list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-LEAVE-002",
|
|
"variantId": "V25-EMP-LEAVE-002",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Leave",
|
|
"role": "All roles",
|
|
"scenario": "Leave balances list loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-LEAVE-002 Leave balances list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-LEAVE-003",
|
|
"variantId": "V25-EMP-LEAVE-003",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Leave",
|
|
"role": "All roles",
|
|
"scenario": "Leave requests list (pending) loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-LEAVE-003 Leave requests list (pending) loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-LEAVE-004",
|
|
"variantId": "V25-EMP-LEAVE-004",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Leave",
|
|
"role": "All roles",
|
|
"scenario": "Leave requests list (all) loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-LEAVE-004 Leave requests list (all) loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-LEAVE-005",
|
|
"variantId": "V25-EMP-LEAVE-005",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Leave",
|
|
"role": "All roles",
|
|
"scenario": "Leave review CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-LEAVE-005 Leave review CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-OB-001",
|
|
"variantId": "V25-EMP-OB-001",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-OB",
|
|
"role": "All roles",
|
|
"scenario": "Onboarding checklist template page loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-OB-001 Onboarding checklist template page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-OB-002",
|
|
"variantId": "V25-EMP-OB-002",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-OB",
|
|
"role": "All roles",
|
|
"scenario": "Onboarding tasks list loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-OB-002 Onboarding tasks list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-OB-003",
|
|
"variantId": "V25-EMP-OB-003",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-OB",
|
|
"role": "All roles",
|
|
"scenario": "Offboarding requests list loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-OB-003 Offboarding requests list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-OB-004",
|
|
"variantId": "V25-EMP-OB-004",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-OB",
|
|
"role": "All roles",
|
|
"scenario": "Registration requests list loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-OB-004 Registration requests list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-OB-005",
|
|
"variantId": "V25-EMP-OB-005",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-OB",
|
|
"role": "All roles",
|
|
"scenario": "Registration request detail loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-OB-005 Registration request detail loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-DOC-001",
|
|
"variantId": "V25-EMP-DOC-001",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-DOC",
|
|
"role": "All roles",
|
|
"scenario": "Document types list loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-DOC-001 Document types list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-DOC-002",
|
|
"variantId": "V25-EMP-DOC-002",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-DOC",
|
|
"role": "All roles",
|
|
"scenario": "Employee documents list loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-DOC-002 Employee documents list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-DOC-003",
|
|
"variantId": "V25-EMP-DOC-003",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-DOC",
|
|
"role": "All roles",
|
|
"scenario": "Executable upload to employee documents is blocked",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-DOC-003 Executable upload to employee documents is blocked",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-DOC-004",
|
|
"variantId": "V25-EMP-DOC-004",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-DOC",
|
|
"role": "All roles",
|
|
"scenario": "Document review CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-DOC-004 Document review CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-PAY-001",
|
|
"variantId": "V25-EMP-PAY-001",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Payroll",
|
|
"role": "All roles",
|
|
"scenario": "Salary structures list loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-PAY-001 Salary structures list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-PAY-002",
|
|
"variantId": "V25-EMP-PAY-002",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Payroll",
|
|
"role": "All roles",
|
|
"scenario": "Payroll runs list loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-PAY-002 Payroll runs list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-PAY-003",
|
|
"variantId": "V25-EMP-PAY-003",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Payroll",
|
|
"role": "All roles",
|
|
"scenario": "Payslips list loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-PAY-003 Payslips list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-PAY-004",
|
|
"variantId": "V25-EMP-PAY-004",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Payroll",
|
|
"role": "All roles",
|
|
"scenario": "Payslips filtered by run loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-PAY-004 Payslips filtered by run loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-PAY-005",
|
|
"variantId": "V25-EMP-PAY-005",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Payroll",
|
|
"role": "All roles",
|
|
"scenario": "Payroll run generate CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-PAY-005 Payroll run generate CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-PAY-006",
|
|
"variantId": "V25-EMP-PAY-006",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Payroll",
|
|
"role": "All roles",
|
|
"scenario": "Payroll run approve CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-PAY-006 Payroll run approve CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-WORK-001",
|
|
"variantId": "V25-EMP-WORK-001",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-WORK",
|
|
"role": "All roles",
|
|
"scenario": "Work allocation dashboard loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-WORK-001 Work allocation dashboard loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-WORK-002",
|
|
"variantId": "V25-EMP-WORK-002",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-WORK",
|
|
"role": "All roles",
|
|
"scenario": "Engagement progress dashboard loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-WORK-002 Engagement progress dashboard loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-WORK-003",
|
|
"variantId": "V25-EMP-WORK-003",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "EMP-WORK",
|
|
"role": "All roles",
|
|
"scenario": "HR Excel imports page loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-WORK-003 HR Excel imports page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ESS-001",
|
|
"variantId": "V25-EMP-ESS-001",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employee Self Service",
|
|
"role": "Staff",
|
|
"scenario": "ESS dashboard loads for Staff",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ESS-001 ESS dashboard loads for Staff",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ESS-002",
|
|
"variantId": "V25-EMP-ESS-002",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employee Self Service",
|
|
"role": "All roles",
|
|
"scenario": "My attendance page loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ESS-002 My attendance page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ESS-003",
|
|
"variantId": "V25-EMP-ESS-003",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employee Self Service",
|
|
"role": "All roles",
|
|
"scenario": "My leave page loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ESS-003 My leave page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ESS-004",
|
|
"variantId": "V25-EMP-ESS-004",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employee Self Service",
|
|
"role": "All roles",
|
|
"scenario": "My documents page loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ESS-004 My documents page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ESS-005",
|
|
"variantId": "V25-EMP-ESS-005",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employee Self Service",
|
|
"role": "All roles",
|
|
"scenario": "My payslips page loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ESS-005 My payslips page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ESS-006",
|
|
"variantId": "V25-EMP-ESS-006",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employee Self Service",
|
|
"role": "All roles",
|
|
"scenario": "My work kanban loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ESS-006 My work kanban loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ESS-007",
|
|
"variantId": "V25-EMP-ESS-007",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employee Self Service",
|
|
"role": "All roles",
|
|
"scenario": "My offboarding page loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ESS-007 My offboarding page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ESS-008",
|
|
"variantId": "V25-EMP-ESS-008",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employee Self Service",
|
|
"role": "All roles",
|
|
"scenario": "My profile page loads",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ESS-008 My profile page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ESS-009",
|
|
"variantId": "V25-EMP-ESS-009",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employee Self Service",
|
|
"role": "All roles",
|
|
"scenario": "Employee registration form loads for unlinked user",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ESS-009 Employee registration form loads for unlinked user",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-ESS-010",
|
|
"variantId": "V25-EMP-ESS-010",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employee Self Service",
|
|
"role": "All roles",
|
|
"scenario": "Leave application CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-ESS-010 Leave application CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-RBAC-001",
|
|
"variantId": "V25-EMP-RBAC-001",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - RBAC",
|
|
"role": "Staff",
|
|
"scenario": "Staff cannot access HR dashboard",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-RBAC-001 Staff cannot access HR dashboard",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-RBAC-002",
|
|
"variantId": "V25-EMP-RBAC-002",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - RBAC",
|
|
"role": "Staff",
|
|
"scenario": "Staff cannot access employee list",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-RBAC-002 Staff cannot access employee list",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-RBAC-003",
|
|
"variantId": "V25-EMP-RBAC-003",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - RBAC",
|
|
"role": "Staff",
|
|
"scenario": "Staff cannot access payroll runs",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-RBAC-003 Staff cannot access payroll runs",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-RBAC-004",
|
|
"variantId": "V25-EMP-RBAC-004",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - RBAC",
|
|
"role": "Client",
|
|
"scenario": "Client cannot access employee portal",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-RBAC-004 Client cannot access employee portal",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-RBAC-005",
|
|
"variantId": "V25-EMP-RBAC-005",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - RBAC",
|
|
"role": "Anonymous",
|
|
"scenario": "Anonymous cannot access any employee route",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-RBAC-005 Anonymous cannot access any employee route",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-SEC-001",
|
|
"variantId": "V25-EMP-SEC-001",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Security",
|
|
"role": "All roles",
|
|
"scenario": "Non-existent employee ID returns safe response",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-SEC-001 Non-existent employee ID returns safe response",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-SEC-002",
|
|
"variantId": "V25-EMP-SEC-002",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Security",
|
|
"role": "All roles",
|
|
"scenario": "Non-existent payroll run ID returns safe response",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-SEC-002 Non-existent payroll run ID returns safe response",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-SEC-003",
|
|
"variantId": "V25-EMP-SEC-003",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Security",
|
|
"role": "All roles",
|
|
"scenario": "HR import commit without preview session is rejected safely",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-SEC-003 HR import commit without preview session is rejected safely",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "UAT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "EMP-SEC-004",
|
|
"variantId": "V25-EMP-SEC-004",
|
|
"sheet": "UAT_Employees_v2_5",
|
|
"module": "Employees - Security",
|
|
"role": "Staff",
|
|
"scenario": "Payroll run generate by Staff is blocked",
|
|
"steps": "Execute Playwright v2.5 module test: EMP-SEC-004 Payroll run generate by Staff is blocked",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-001",
|
|
"variantId": "V25-CASE-001",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "All roles",
|
|
"scenario": "Notice case list loads",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-001 Notice case list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-002",
|
|
"variantId": "V25-CASE-002",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "All roles",
|
|
"scenario": "Notice case detail page loads",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-002 Notice case detail page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-003",
|
|
"variantId": "V25-CASE-003",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "All roles",
|
|
"scenario": "Notice case edit page loads",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-003 Notice case edit page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-004",
|
|
"variantId": "V25-CASE-004",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "All roles",
|
|
"scenario": "Notice case events sub-page loads",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-004 Notice case events sub-page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-005",
|
|
"variantId": "V25-CASE-005",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "All roles",
|
|
"scenario": "Notice case hearings sub-page loads",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-005 Notice case hearings sub-page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-006",
|
|
"variantId": "V25-CASE-006",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "All roles",
|
|
"scenario": "Notice case orders sub-page loads",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-006 Notice case orders sub-page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-007",
|
|
"variantId": "V25-CASE-007",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "All roles",
|
|
"scenario": "Notice case document download requires auth",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-007 Notice case document download requires auth",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-008",
|
|
"variantId": "V25-CASE-008",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "All roles",
|
|
"scenario": "Notice case document delete CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-008 Notice case document delete CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-009",
|
|
"variantId": "V25-CASE-009",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "All roles",
|
|
"scenario": "Notice case upload CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-009 Notice case upload CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-010",
|
|
"variantId": "V25-CASE-010",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "Client",
|
|
"scenario": "Client cannot access notice cases",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-010 Client cannot access notice cases",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-011",
|
|
"variantId": "V25-CASE-011",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "All roles",
|
|
"scenario": "IDOR: cross-case document download blocked",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-011 IDOR: cross-case document download blocked",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "CASE-012",
|
|
"variantId": "V25-CASE-012",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Notice Cases",
|
|
"role": "All roles",
|
|
"scenario": "Non-existent case detail returns safe response",
|
|
"steps": "Execute Playwright v2.5 module test: CASE-012 Non-existent case detail returns safe response",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-001",
|
|
"variantId": "V25-SVC-001",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Bulk imports page loads",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-001 Bulk imports page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-002",
|
|
"variantId": "V25-SVC-002",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Bulk imports service-master template downloads",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-002 Bulk imports service-master template downloads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-003",
|
|
"variantId": "V25-SVC-003",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Bulk imports engagement-assignments template downloads",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-003 Bulk imports engagement-assignments template downloads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-004",
|
|
"variantId": "V25-SVC-004",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Bulk imports firm-task-templates template downloads",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-004 Bulk imports firm-task-templates template downloads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-005",
|
|
"variantId": "V25-SVC-005",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Bulk import preview CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-005 Bulk import preview CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-006",
|
|
"variantId": "V25-SVC-006",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Subscription detail loads",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-006 Subscription detail loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-007",
|
|
"variantId": "V25-SVC-007",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Subscription edit page loads",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-007 Subscription edit page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-008",
|
|
"variantId": "V25-SVC-008",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Subscription lock CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-008 Subscription lock CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-009",
|
|
"variantId": "V25-SVC-009",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Bulk lock CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-009 Bulk lock CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-010",
|
|
"variantId": "V25-SVC-010",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Subscription generate CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-010 Subscription generate CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-011",
|
|
"variantId": "V25-SVC-011",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "Client",
|
|
"scenario": "Client cannot access services admin",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-011 Client cannot access services admin",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-012",
|
|
"variantId": "V25-SVC-012",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Non-existent subscription ID returns safe response",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-012 Non-existent subscription ID returns safe response",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "SVC-013",
|
|
"variantId": "V25-SVC-013",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Services",
|
|
"role": "All roles",
|
|
"scenario": "Task bulk-update CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: SVC-013 Task bulk-update CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "WORK-001",
|
|
"variantId": "V25-WORK-001",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Workspaces",
|
|
"role": "All roles",
|
|
"scenario": "Engagement work detail page loads",
|
|
"steps": "Execute Playwright v2.5 module test: WORK-001 Engagement work detail page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "WORK-002",
|
|
"variantId": "V25-WORK-002",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Workspaces",
|
|
"role": "All roles",
|
|
"scenario": "Task status update CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: WORK-002 Task status update CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "WORK-003",
|
|
"variantId": "V25-WORK-003",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Workspaces",
|
|
"role": "All roles",
|
|
"scenario": "Task comment POST CSRF-less is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: WORK-003 Task comment POST CSRF-less is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "WORK-004",
|
|
"variantId": "V25-WORK-004",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Workspaces",
|
|
"role": "All roles",
|
|
"scenario": "Task comments list page loads",
|
|
"steps": "Execute Playwright v2.5 module test: WORK-004 Task comments list page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "WORK-005",
|
|
"variantId": "V25-WORK-005",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Workspaces",
|
|
"role": "All roles",
|
|
"scenario": "Task edit page loads",
|
|
"steps": "Execute Playwright v2.5 module test: WORK-005 Task edit page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "WORK-006",
|
|
"variantId": "V25-WORK-006",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Workspaces",
|
|
"role": "All roles",
|
|
"scenario": "Task upload CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: WORK-006 Task upload CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "WORK-007",
|
|
"variantId": "V25-WORK-007",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Workspaces",
|
|
"role": "All roles",
|
|
"scenario": "Non-existent task returns safe response",
|
|
"steps": "Execute Playwright v2.5 module test: WORK-007 Non-existent task returns safe response",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "WORK-008",
|
|
"variantId": "V25-WORK-008",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Workspaces",
|
|
"role": "Staff",
|
|
"scenario": "IDOR: Staff cannot update task assigned to another user via direct POST",
|
|
"steps": "Execute Playwright v2.5 module test: WORK-008 IDOR: Staff cannot update task assigned to another user via direct POST",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "WORK-009",
|
|
"variantId": "V25-WORK-009",
|
|
"sheet": "UAT_NoticeCases_Services_Work_v2_5",
|
|
"module": "Workspaces",
|
|
"role": "Client",
|
|
"scenario": "Client cannot access work detail",
|
|
"steps": "Execute Playwright v2.5 module test: WORK-009 Client cannot access work detail",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "PART-001",
|
|
"variantId": "V25-PART-001",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Partners",
|
|
"role": "Partner",
|
|
"scenario": "Partner dashboard loads",
|
|
"steps": "Execute Playwright v2.5 module test: PART-001 Partner dashboard loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "PART-002",
|
|
"variantId": "V25-PART-002",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Partners",
|
|
"role": "Partner",
|
|
"scenario": "Partner client list loads",
|
|
"steps": "Execute Playwright v2.5 module test: PART-002 Partner client list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "PART-003",
|
|
"variantId": "V25-PART-003",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Partners",
|
|
"role": "Partner",
|
|
"scenario": "Partner reviews list loads",
|
|
"steps": "Execute Playwright v2.5 module test: PART-003 Partner reviews list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "PART-004",
|
|
"variantId": "V25-PART-004",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Partners",
|
|
"role": "Partner",
|
|
"scenario": "Partner task review page loads",
|
|
"steps": "Execute Playwright v2.5 module test: PART-004 Partner task review page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "PART-005",
|
|
"variantId": "V25-PART-005",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Partners",
|
|
"role": "Partner",
|
|
"scenario": "Partner task review CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: PART-005 Partner task review CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "PART-006",
|
|
"variantId": "V25-PART-006",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Partners",
|
|
"role": "Partner",
|
|
"scenario": "Staff cannot access partner dashboard",
|
|
"steps": "Execute Playwright v2.5 module test: PART-006 Staff cannot access partner dashboard",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "PART-007",
|
|
"variantId": "V25-PART-007",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Partners",
|
|
"role": "Partner",
|
|
"scenario": "Client cannot access partner reviews",
|
|
"steps": "Execute Playwright v2.5 module test: PART-007 Client cannot access partner reviews",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "PART-008",
|
|
"variantId": "V25-PART-008",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Partners",
|
|
"role": "Partner",
|
|
"scenario": "Anonymous access to partner dashboard is blocked",
|
|
"steps": "Execute Playwright v2.5 module test: PART-008 Anonymous access to partner dashboard is blocked",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "PART-009",
|
|
"variantId": "V25-PART-009",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Partners",
|
|
"role": "All roles",
|
|
"scenario": "Non-existent task review ID returns safe response",
|
|
"steps": "Execute Playwright v2.5 module test: PART-009 Non-existent task review ID returns safe response",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-001",
|
|
"variantId": "V25-BILL-001",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "Firm Admin",
|
|
"scenario": "Invoice list loads for Firm Admin",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-001 Invoice list loads for Firm Admin",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-002",
|
|
"variantId": "V25-BILL-002",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "Invoice create form loads",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-002 Invoice create form loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-003",
|
|
"variantId": "V25-BILL-003",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "Invoice detail page loads",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-003 Invoice detail page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-004",
|
|
"variantId": "V25-BILL-004",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "Invoice print page loads",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-004 Invoice print page loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-005",
|
|
"variantId": "V25-BILL-005",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "Invoice payments subpage loads",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-005 Invoice payments subpage loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-006",
|
|
"variantId": "V25-BILL-006",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "Payment receipt loads",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-006 Payment receipt loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-007",
|
|
"variantId": "V25-BILL-007",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "Payments list loads",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-007 Payments list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-008",
|
|
"variantId": "V25-BILL-008",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "Fee structures list loads",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-008 Fee structures list loads",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Medium",
|
|
"type": "Regression",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-009",
|
|
"variantId": "V25-BILL-009",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "Invoice post CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-009 Invoice post CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-010",
|
|
"variantId": "V25-BILL-010",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "New payment CSRF-less POST is rejected",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-010 New payment CSRF-less POST is rejected",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-011",
|
|
"variantId": "V25-BILL-011",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "Staff",
|
|
"scenario": "Staff cannot access invoice list",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-011 Staff cannot access invoice list",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-012",
|
|
"variantId": "V25-BILL-012",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "Client",
|
|
"scenario": "Client cannot access billing admin",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-012 Client cannot access billing admin",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-013",
|
|
"variantId": "V25-BILL-013",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "Anonymous",
|
|
"scenario": "Anonymous access to billing is blocked",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-013 Anonymous access to billing is blocked",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-014",
|
|
"variantId": "V25-BILL-014",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "Non-existent invoice ID returns safe response",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-014 Non-existent invoice ID returns safe response",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "Critical",
|
|
"type": "VAPT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-015",
|
|
"variantId": "V25-BILL-015",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "Invoice create with blank form shows validation, not 500",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-015 Invoice create with blank form shows validation, not 500",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "UAT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
},
|
|
{
|
|
"sourceId": "BILL-016",
|
|
"variantId": "V25-BILL-016",
|
|
"sheet": "UAT_Partners_Billing_v2_5",
|
|
"module": "Billing",
|
|
"role": "All roles",
|
|
"scenario": "Fee structure import template download works",
|
|
"steps": "Execute Playwright v2.5 module test: BILL-016 Fee structure import template download works",
|
|
"expected": "Route/action completes safely according to ERP permission and validation rules; no server 500 or unauthorized data exposure.",
|
|
"priority": "High",
|
|
"type": "UAT",
|
|
"route": "",
|
|
"variantName": "v2.5 new module automated check",
|
|
"variantType": "v2_5",
|
|
"automation": "automated",
|
|
"manualReason": ""
|
|
}
|
|
] |