10
Admin Panel
UAT-10.1
Admin Access Control
CriticalSteps
- Log in as a non-admin user, try to access /admin
- Log in as an admin user, access /admin
Verify (4 checks)
- Non-admin user is blocked from accessing admin panel (403 or redirect)
- Admin user can access the admin panel
- Admin panel shows user management section
- Admin panel shows audit logs
| Score | Tester | Date | Notes |
|---|---|---|---|
| ___ | ___ | ___ | ___ |
UAT-10.2
User Management
HighSteps
- Navigate to Admin > Users
- View the user list
- Change a user's role
Verify (6 checks)
- All registered users are listed
- Each user shows: name, email, role, creation date
- Can change a user's role (user -> admin, admin -> user)
- Role change takes effect immediately
- Audit log entry is created for the role change
- Cannot remove admin role from the last admin (safety check)
| Score | Tester | Date | Notes |
|---|---|---|---|
| ___ | ___ | ___ | ___ |
UAT-10.3
Audit Logs
MediumSteps
- Navigate to Admin > Audit Logs
- Review the log entries
Verify (4 checks)
- Audit logs are displayed in reverse chronological order
- Each entry shows: timestamp, user, action, target, IP address
- Actions logged include: role changes, document deletions, admin access
- Logs cannot be modified or deleted by any user
| Score | Tester | Date | Notes |
|---|---|---|---|
| ___ | ___ | ___ | ___ |