# Learn API testing

Short lessons on API and database tests. Each lesson solves one test problem with one zriz pipeline that you can copy.

1. [Test an API status code and response body](https://zriz.io/learn/test-api-status-code-and-body.md): Check the status code and the fields of the result in one zriz pipeline. A test that reads only the status code misses a wrong body.
2. [Test that a bad request returns 400](https://zriz.io/learn/test-api-400-bad-request.md): Send a broken request on purpose in a zriz pipeline. Check for status 400 and the exact error text, so a bad input never gets a 500 or a 201.
3. [Test that an API returns 401 without a token](https://zriz.io/learn/test-api-401-without-token.md): Call a protected endpoint with no token and with a bad token in one zriz pipeline. Each call must get status 401 and no data.
4. [Test API authorization between two users](https://zriz.io/learn/test-api-authorization-between-users.md): Make two users in one zriz pipeline. User A creates an order, then user B asks for it. The API must refuse user B: this finds broken access control.
5. [Test that duplicate requests create one row](https://zriz.io/learn/test-duplicate-requests-create-one-row.md): Send one request three times in a zriz pipeline, then count the rows in the database. One row proves that a retry makes no duplicate.
6. [Test that a failed request writes no row](https://zriz.io/learn/test-failed-request-writes-no-row.md): Send a bad request in a zriz pipeline, then query the database. Status 400 and zero rows prove that a refused request stores nothing.
7. [Test a login flow from sign-up to token](https://zriz.io/learn/test-login-flow-with-token.md): Chain three calls in one zriz pipeline: sign up, log in, then use the token of the login. The flow passes only when each part works with the next.
8. [Test that a password is stored as a hash](https://zriz.io/learn/test-password-stored-as-hash.md): Sign up in a zriz pipeline, then read the user row. The test fails if a result holds the password or the database holds it as plain text.
9. [Test an async API with polling, not sleep](https://zriz.io/learn/test-async-api-with-polling.md): Use the poll step of a zriz pipeline to wait for an async result. The test ends when the result comes, and fails if it never does.
10. [Test that a missing record returns 404](https://zriz.io/learn/test-api-404-not-found.md): Ask for a record that does not exist in a zriz pipeline. The API must answer 404 with an error, not 500 and not 200 with an empty body.
