zrizDocsLearnSecuritySign inSign up

Learn API testing

Short lessons on API and database tests. Each lesson solves one test problem with one zriz pipeline that you can copy.

  1. Test an API status code and response body Check the status code and the fields of the result in one zriz pipeline. A test that reads only the status code misses a wrong body.
  2. Test that a bad request returns 400 Send a broken request on purpose in a zriz pipeline. Check for status 400 and the exact error text, so a bad input never gets a 500 or a 201.
  3. Test that an API returns 401 without a token Call a protected endpoint with no token and with a bad token in one zriz pipeline. Each call must get status 401 and no data.
  4. Test API authorization between two users Make two users in one zriz pipeline. User A creates an order, then user B asks for it. The API must refuse user B: this finds broken access control.
  5. Test that duplicate requests create one row Send one request three times in a zriz pipeline, then count the rows in the database. One row proves that a retry makes no duplicate.
  6. Test that a failed request writes no row Send a bad request in a zriz pipeline, then query the database. Status 400 and zero rows prove that a refused request stores nothing.
  7. Test a login flow from sign-up to token Chain three calls in one zriz pipeline: sign up, log in, then use the token of the login. The flow passes only when each part works with the next.
  8. Test that a password is stored as a hash Sign up in a zriz pipeline, then read the user row. The test fails if a result holds the password or the database holds it as plain text.
  9. Test an async API with polling, not sleep Use the poll step of a zriz pipeline to wait for an async result. The test ends when the result comes, and fails if it never does.
  10. Test that a missing record returns 404 Ask for a record that does not exist in a zriz pipeline. The API must answer 404 with an error, not 500 and not 200 with an empty body.