Pentest-AI
Field notes

Test beyond the login page

A reachable route is not the same thing as a route tested with the right identity.

Updated 12 September 2026

A login page is not the application

An unauthenticated scan may reach public routes while missing the workflows available to signed-in users. Coverage also changes with role, object ownership and the state of a session.

A user who can read their own record is not necessarily allowed to read someone else's. Testing that distinction needs appropriate test identities and objects, not just a successful HTTP response.

Make the identity explicit

Pentest-AI supports authentication inputs and named authentication profiles. Inspect the options in your installed version:

ptai start --help
ptai auth profile --help

Use dedicated test accounts and only permissions included in the engagement scope. Keep passwords and tokens out of public logs and command examples. Do not assume that a logged-in response proves the intended role was tested.

Check the control

For an access-control finding, the useful evidence is the difference between an allowed action and a disallowed one under comparable conditions. A redirect, a generic success page or stale session state can otherwise obscure the result.

Review what was actually requested and returned. Unsupported checks can remain candidates for a human to investigate.

How Pentest-AI verifies a finding →

Found something unclear?Open an issue ↗