zrizDocsLearnSecuritySign inSign up

Test that a bad request returns 400

Send a broken request on purpose in a zriz pipeline. Check for status 400 and the exact error text, so a bad input never gets a 500 or a 201.

Lesson 2 of 10 · zz 0.8.0 or later · Updated · Plain text for agents: /learn/test-api-400-bad-request.md

The problem

A request with a missing field must get 400 and a clear error. Without a test, a change can turn that result into 500. Or the API accepts the bad data and stores it.

The test

The example is a shop API. POST /api/auth/register needs email, password, and name. The test sends no name.

Start from a project that zz init made: the quick start gives the commands. Add the action register to the resource file.

.zriz/resources/target.json:

{
  "type": "http",
  "description": "Your app under test",
  "base-url": "${env.TARGET_URL}",
  "headers": { "Content-Type": "application/json" },
  "actions": {
    "check": { "method": "GET", "path": "/api/health" },
    "register": { "method": "POST", "path": "/api/auth/register" }
  }
}

.zriz/pipelines/register-bad-request.json:

{
  "description": "Sign up with no name: the API must answer 400",
  "steps": [
    { "set": { "email": "u-${gen.uuid}@test.com" } },
    {
      "call": "target/register",
      "body": { "email": "${ctx.email}", "password": "secret123" },
      "expect": [
        ["status", "==", 400],
        ["body.error", "==", "email, password, and name are required"],
        ["body.token", "not-exists"]
      ]
    }
  ]
}

Run it

zz run register-bad-request
"status":"pass"

What it proves

Common mistake: A check of only status >= 400 passes on a 500. Compare with the exact code.

Next