This repository contains an automated API testing suite for the Restful-Booker API.
The framework uses Postman collections, JavaScript assertions, environment variables, Newman command-line execution, HTML reporting, and GitHub Actions. It covers API health, authentication, booking retrieval, the complete booking lifecycle, authorization checks, response schemas, data integrity, and exploratory validation findings.
Stable regression tests and exploratory findings are executed separately. Only the stable regression suite runs in the CI workflow.
- Postman: API client used to configure HTTP requests, build test collections, and write JavaScript assertions (
pm.test,pm.expect). - Newman: Command-line runner used to execute Postman collections headlessly in the CLI and CI pipelines.
- Newman Reporter HTMLExtra: Newman extension that exports test run results into detailed HTML reports.
- Node.js & npm: JavaScript runtime environment and package manager used to run scripts and manage dependencies.
- GitHub Actions: CI/CD platform that runs the test suite automatically on clean virtual environments upon push and pull request events.
- API Chaining: Eliminates hardcoded dynamic data by passing runtime variables from POST responses into GET, PUT, PATCH, and DELETE requests.
- Schema Validation: Utilizes strict JSON Schema assertions to validate structural integrity, data types, required keys, and date format patterns.
- Environment Isolation: Separates variables from collection structures to allow running the suite seamlessly across different environments.
- Negative Testing: Validates authentication failures, invalid booking identifiers, and unauthorized modification attempts.
- Exploratory API Testing: Evaluates undocumented validation boundaries separately from the stable regression suite.
- Result Separation: Runs confirmed behavior in CI and keeps exploratory findings in a separate test run.
| Collection | Requests | Active Assertions | Purpose |
|---|---|---|---|
| 00 Health Check | 1 | 1 | Confirms that the API is available before executing the main tests. |
| 01 Authentication | 1 | 3 | Validates successful authentication and stores the generated token. |
| 02 Booking CRUD | 6 | 23 | Retrieves booking IDs and validates booking creation, retrieval, partial update, full update, deletion, schemas, and data integrity. |
| 03 Negatives & Edge Cases | 4 | 6 | Validates invalid credentials, invalid booking IDs, and unauthorized modification attempts. |
| 04 Exploratory Findings | 11 | 11 | Evaluates malformed payloads, date validation, numeric boundaries, and unusual string input. |
| Total | 23 | 44 | Stable regression and exploratory coverage |
The Delete Booking test performs an additional
GETrequest throughpm.sendRequestto verify that the deleted record returns404.
The collection separates established application behavior from requirement-dependent exploratory expectations.
The stable suite validates behavior currently established by the Restful-Booker API, including several API-specific response conventions:
- Successful booking creation returns
200 OK. - Successful booking deletion returns
201 Created. - Invalid authentication returns
200 OKwith a rejection reason and no authentication token.
These responses differ from common REST conventions, but they are treated as established application behavior rather than confirmed defects.
The stable suite runs on every push and pull request and controls the GitHub Actions result.
The exploratory suite evaluates behaviors for which formal business requirements and acceptance criteria are unavailable, including:
- Null and missing required values
- Invalid and inverted booking dates
- Negative and unusually large price values
- Zero-price bookings
- Emoji and symbol input
- Script-like string input
Assertions remain active so the report shows both observed behavior and differences from the proposed expectations.
These findings are not presented as confirmed defects. They represent validation risks or requirement questions that would require product clarification in a production project.
Clone the repository and install dependencies locally:
git clone https://github.com/danielbxs/rb-api-test-suite
cd rb-api-test-suite
npm installRuns the stable regression suite
npm run testRuns the suite and compiles an interactive HTML report inside the reports/ folder:
npm run test-reportThis command may exit with failed assertions when the exploratory findings are reproduced. These failures are intentional and do not indicate a problem with the test framework.
npm run test-findingsThe report is generated at reports/exploratory-findings.html.
npm run test-findings-report- Health check
npm run test-health- Auth
npm run test-auth- Crud
npm run test-crud- Edge cases
npm run test-edge