Key risks covered
- - Valid create request, required fields, request schema, and 201 Created response.
- - Duplicate email, invalid email, weak password, malformed JSON, and wrong content type.
- - Protected fields, default role/status, mass assignment, and role escalation prevention.
- - Password hashing, password not returned, password not logged, and safe audit records.
- - Tenant isolation, database persistence, welcome or verification email failures, retries, and rate limits.