SI Store Ops

Inspectable example · updated 2026-10-11

Synthetic example: a members-only access matrix with one leak that only appears from the cache

An invented test grid for a made-up course site, showing expected and actual access and the cached sequence that exposes a fault.

An example, not a customer case study. Scope and evidence limitations are described below.

The invented site

A made-up online course site has four test accounts and four protected items. All accounts are fake and exist only on a staging copy. The items are a free preview page, a Level 1 lesson page, a Level 2 lesson page and a Level 2 downloadable workbook. Expected results are written before testing. Everything below is invented to show a method.

  • Accounts: logged-out, Level 1 member, Level 2 member, expired member.
  • Items: preview, lesson 1, lesson 2, workbook file address.

The grid

Each cell shows expected, then actual. "ok" means they match. Anything else is a finding.

  • A = allowed, D = denied. Read each cell as expected/actual.

If the matrix is wider than the box, scroll horizontally to read every column. Keyboard: focus the matrix and use Left/Right.

account         | preview | lesson 1 | lesson 2 | workbook
logged-out      | A/A ok  | D/D ok   | D/D ok   | D/A  <- finding
Level 1 member  | A/A ok  | A/A ok   | D/D ok   | D/D ok
Level 2 member  | A/A ok  | A/A ok   | A/A ok   | A/A ok
expired member  | A/A ok  | D/A  <-  | D/D ok   | D/D ok

Reading the findings

Two cells fail. A logged-out visitor can fetch the workbook through its direct file address, which means the page that links to the file is protected but the file is not. An expired member still reads lesson 1, which suggests their level expiry did not apply, a task a scheduler may have missed or a role that was not updated. The grid does not say which; it shows where to look next. The fix for each goes on a staging copy first, then the grid is run again in full.

  • A protected page does not automatically protect the file it links to; test the file address.
  • An expired level that still has access points to the expiry mechanism or to caching.

The sequence that exposes caching

A second test makes three requests to lesson 2 in a row on a staging copy with page caching enabled as on the live site: logged-out, then Level 2 member, then logged-out again. Expected: deny, allow, deny. Actual in this invented run: deny, allow, allow. The second logged-out request received the member's cached copy. That is a caching fault, not a rule fault, and no amount of editing the access rules would fix it.

  • Run the sequence at least twice, with the cache cleared before the first.
  • Record what each response actually contained, not only the status.

What this example does not prove

It is not a real site, test or fault, and the cells are invented. A passing grid is evidence for the cells tested, not a guarantee that nothing leaks, and it cannot recall copies of content others already hold. Real tests also cover archives, search, feeds and the data interface for a logged-out request. The workbook finding is realistic only as an illustration of testing the file address separately.

  • Do not infer that your site has either fault.

Use it to specify an enquiry

Send the membership plugin's name, the account types, the items to protect and examples of wrong access. The access job has a published test price of GBP 395 for one plugin, up to four levels and ten items, using made-up accounts on staging. If members paid but their level did not change, the payment-to-access job fits better. Prices are untested proposals and payment follows the agreed checks.

  • Send lists and descriptions, never real member data.

Sources and limits