Skip to content
julietaMendez edited this page May 9, 2022 · 1 revision

THIS PAGE WILL BE USED FOR DRAFTS!

For Requirements and Tests, the following will be split into sections according to their micro service.
If required, each section will be further divided up into classes

Requirements/Functionalities

Accounts

  • Business Account Creation
    • Business Account created with an Admin Account
  • Admin Account Creation
    • Must be created with a valid Business ID
    • Created by Another Admin
    • Reflect account creation in Business Account Data
  • Employee Account Creation
    • Must be created with valid Business ID
    • Created by an Admin account
    • Reflect account creation in Business Account Data
  • Save Report Format information
    • Save with business account info
    • Only done from an admin account
  • Account Deletion
    • Drop account info from database
    • Modify Business account info to reflect this
    • Only done from an admin account
  • Account Info retrieval
    • Retrieve Email, Hashed Password, First Name, Last Name, Business ID
  • Login
  • Logout
  • Set Permissions
    • Only done by an admin
    • Permissions only apply to Employee Accounts
  • Retrieve Permissions
    • Used for authorizations
  • Edit Account Info
    • Email, First name, Last name, password
    • Business ID CANNOT be changed

Authorization/Authentication

Reports

Images

Notifications

Security Measures

Accounts

  • Worker Account Creation
    • Each Password must be hashed, will be using BCrypts hashing algo with 10 rounds
      *Business Account Creation
    • Business Accounts cannot be created without also creating an admin account
    • Conversely, an Admin account cannot be created with out a business id
      • To deal with this, there will be a special registration function that will override this for Admin account creation
  • Permissions
    • Permissions can only be set or changed by an admin account, to ensure this, the admin account that is changing the permissions will be passed as a parameter along with the set of permissions to save to the Employee account receiving the changes
    • Admins by default have no 'permissions' associated with their account and are allowed full access
  • Login/Logout
    • Password validation will be done on accounts, then grab an authentication token from the Auth microservice.
    • Log out on token validation fail
  • Report Format updating
    • Type of account requesting change will be checked, and must be an AdminAccount.
    • Report formats saved with Business account, and can only be changed by a valid AdminAccount
  • Account Deletion/Promotion
    • These processes require an AdminAccount to be the requester. This will fail if its EmployeeAccount.
    • These actions must update the related BusinessAccount data as well.
  • All Requests will require a valid Auth token, even for admin accounts.

Authorization/Authentication

Reports

Images

Notifications

Test Cases

Accounts

Authorization/Authentication

Reports

Images

Notifications

Clone this wiki locally