<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Access Control Testing on ZAP</title>
    <link>/docs/desktop/addons/access-control-testing/</link>
    <description>Recent content in Access Control Testing on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/docs/desktop/addons/access-control-testing/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Access Control Status Tab</title>
      <link>/docs/desktop/addons/access-control-testing/tab/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/desktop/addons/access-control-testing/tab/</guid>
      <description>&lt;h1 id=&#34;access-control-status-tab&#34;&gt;Access Control Status Tab&lt;/h1&gt;&#xA;&lt;p&gt;The Access Control Status Tab allows starting of new Access Control testing and displays the results obtained. For&#xA;each User and for each URL attacked by ZAP, an entry is added with information about:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;ZAP&amp;rsquo;s id of the message sent&lt;/li&gt;&#xA;&lt;li&gt;the HTTP method used&lt;/li&gt;&#xA;&lt;li&gt;the URL of the resource&lt;/li&gt;&#xA;&lt;li&gt;the HTTP status code of the response&lt;/li&gt;&#xA;&lt;li&gt;the User from whose point the resource was accessed&lt;/li&gt;&#xA;&lt;li&gt;whether the request was identified as being authorized or not&lt;/li&gt;&#xA;&lt;li&gt;the access rule used, which was either directly defined or inferred based on parent&amp;rsquo;s defined rules&lt;/li&gt;&#xA;&lt;li&gt;the result obtained: successful (green check) if the access rule was followed of failed (red cross) otherwise&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 id=&#34;see-also&#34;&gt;See also &lt;a class=&#34;header-link&#34; href=&#34;#see-also&#34;&gt;&lt;svg class=&#34;fill-current o-60 hover-accent-color-light&#34; height=&#34;22px&#34; viewBox=&#34;0 0 24 24&#34; width=&#34;22px&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;path d=&#34;M0 0h24v24H0z&#34; fill=&#34;none&#34;/&gt;&lt;path d=&#34;M3.9 12c0-1.71 1.39-3.1 3.1-3.1h4V7H7c-2.76 0-5 2.24-5 5s2.24 5 5 5h4v-1.9H7c-1.71 0-3.1-1.39-3.1-3.1zM8 13h8v-2H8v2zm9-6h-4v1.9h4c1.71 0 3.1 1.39 3.1 3.1s-1.39 3.1-3.1 3.1h-4V17h4c2.76 0 5-2.24 5-5s-2.24-5-5-5z&#34; fill=&#34;currentColor&#34;/&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;/docs/desktop/addons/access-control-testing/&#34;&gt;Access Control Testing concepts&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;for a short introduction to Access Control Testing&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;/docs/desktop/addons/access-control-testing/contextoptions/&#34;&gt;Access Control Context options&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;to learn about the related context options&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;</description>
    </item>
    <item>
      <title>Access Control Context Options</title>
      <link>/docs/desktop/addons/access-control-testing/contextoptions/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/desktop/addons/access-control-testing/contextoptions/</guid>
      <description>&lt;h1 id=&#34;access-control-context-options&#34;&gt;Access Control Context Options&lt;/h1&gt;&#xA;&lt;p&gt;The Access Control Context options are present as a panel for each Context when opening the Session Properties&#xA;dialog. This panel allows ZAP users to define the Access Rules for each User of each Context.&lt;/p&gt;&#xA;&lt;p&gt;As mentioned on the &lt;a href=&#34;/docs/desktop/addons/access-control-testing/&#34;&gt;concepts&lt;/a&gt; page, ZAP is making use of the tree-based&#xA;structure of URLs. So, when configuring the access rules, only 1 rule needs to be set explicitly for an entire&#xA;subtree, while for the other nodes rules are inferred. Three possible values can be set for any node in Context for&#xA;each User:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
