If we are logged in as a Reader, we can type in the URL of a page (say design report) that a Reader does not have access to and be able to use the feature. This defect is due to the fact that each page checks for existence of User Id in the session and does not check page level access.