zrizDocsLearnSecuritySign inSign up

Test a login flow from sign-up to token

Chain three calls in one zriz pipeline: sign up, log in, then use the token of the login. The flow passes only when each part works with the next.

Lesson 7 of 10 · zz 0.8.0 or later · Updated · Plain text for agents: /learn/test-login-flow-with-token.md

The problem

Each endpoint can pass its own test while the flow is broken. The login gives a token that the next endpoint refuses. A user cannot work, and no unit test fails.

The test

The example is a shop API. The test saves the token of the login and sends it to GET /api/auth/me.

Start from a project that zz init made: the quick start gives the commands. Add three actions to the resource file.

.zriz/resources/target.json:

{
  "type": "http",
  "description": "Your app under test",
  "base-url": "${env.TARGET_URL}",
  "headers": { "Content-Type": "application/json" },
  "actions": {
    "check": { "method": "GET", "path": "/api/health" },
    "register": { "method": "POST", "path": "/api/auth/register" },
    "login": { "method": "POST", "path": "/api/auth/login" },
    "me": { "method": "GET", "path": "/api/auth/me" }
  }
}

.zriz/pipelines/login-flow.json:

{
  "description": "Sign up, log in, then use the token",
  "steps": [
    { "set": { "email": "u-${gen.uuid}@test.com", "password": "secret123" } },
    {
      "call": "target/register",
      "body": { "email": "${ctx.email}", "password": "${ctx.password}", "name": "Ann" },
      "expect": [["status", "==", 201]]
    },
    {
      "call": "target/login",
      "body": { "email": "${ctx.email}", "password": "${ctx.password}" },
      "expect": [["status", "==", 200], ["body.token", "not-empty"]],
      "save": { "token": "body.token" }
    },
    {
      "call": "target/me",
      "headers": { "Authorization": "Bearer ${ctx.token}" },
      "expect": [["status", "==", 200], ["body.email", "==", "${ctx.email}"]]
    },
    {
      "call": "target/login",
      "body": { "email": "${ctx.email}", "password": "wrong-password" },
      "expect": [["status", "==", 401], ["body.token", "not-exists"]]
    }
  ]
}

Run it

zz run login-flow
"status":"pass"

What it proves

Common mistake: A test that uses the token of the sign-up never tests the login. Save the token from the login step.

Next