This is the supporting repository for the blog post over at https://medium.com/asos-techblog/automated-security-testing-using-language-you-already-know-60b968d55cec
When you clone the repo, you will be able to run the web app in localhost, and then run the tests against that instance of localhost.
If you use the article to help explain what is going on, and what extra methodolodies are highlighted over and above the standard BDD style scenarios.