Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Restful-Booker API Tests

Restful-Booker API Test Automation Framework

Overview

This repository contains an automated API testing suite for the Restful-Booker API.

The framework uses Postman collections, JavaScript assertions, environment variables, Newman command-line execution, HTML reporting, and GitHub Actions. It covers API health, authentication, booking retrieval, the complete booking lifecycle, authorization checks, response schemas, data integrity, and exploratory validation findings.

Stable regression tests and exploratory findings are executed separately. Only the stable regression suite runs in the CI workflow.

Technologies Used

  • Postman: API client used to configure HTTP requests, build test collections, and write JavaScript assertions (pm.test, pm.expect).
  • Newman: Command-line runner used to execute Postman collections headlessly in the CLI and CI pipelines.
  • Newman Reporter HTMLExtra: Newman extension that exports test run results into detailed HTML reports.
  • Node.js & npm: JavaScript runtime environment and package manager used to run scripts and manage dependencies.
  • GitHub Actions: CI/CD platform that runs the test suite automatically on clean virtual environments upon push and pull request events.

Test & Scripting Patterns

  • API Chaining: Eliminates hardcoded dynamic data by passing runtime variables from POST responses into GET, PUT, PATCH, and DELETE requests.
  • Schema Validation: Utilizes strict JSON Schema assertions to validate structural integrity, data types, required keys, and date format patterns.
  • Environment Isolation: Separates variables from collection structures to allow running the suite seamlessly across different environments.
  • Negative Testing: Validates authentication failures, invalid booking identifiers, and unauthorized modification attempts.
  • Exploratory API Testing: Evaluates undocumented validation boundaries separately from the stable regression suite.
  • Result Separation: Runs confirmed behavior in CI and keeps exploratory findings in a separate test run.

Test Coverage Table

Collection Requests Active Assertions Purpose
00 Health Check 1 1 Confirms that the API is available before executing the main tests.
01 Authentication 1 3 Validates successful authentication and stores the generated token.
02 Booking CRUD 6 23 Retrieves booking IDs and validates booking creation, retrieval, partial update, full update, deletion, schemas, and data integrity.
03 Negatives & Edge Cases 4 6 Validates invalid credentials, invalid booking IDs, and unauthorized modification attempts.
04 Exploratory Findings 11 11 Evaluates malformed payloads, date validation, numeric boundaries, and unusual string input.
Total 23 44 Stable regression and exploratory coverage

The Delete Booking test performs an additional GET request through pm.sendRequest to verify that the deleted record returns 404.


Test Result Strategy

The collection separates established application behavior from requirement-dependent exploratory expectations.

Stable regression suite

The stable suite validates behavior currently established by the Restful-Booker API, including several API-specific response conventions:

  • Successful booking creation returns 200 OK.
  • Successful booking deletion returns 201 Created.
  • Invalid authentication returns 200 OK with a rejection reason and no authentication token.

These responses differ from common REST conventions, but they are treated as established application behavior rather than confirmed defects.

The stable suite runs on every push and pull request and controls the GitHub Actions result.

Exploratory findings

The exploratory suite evaluates behaviors for which formal business requirements and acceptance criteria are unavailable, including:

  • Null and missing required values
  • Invalid and inverted booking dates
  • Negative and unusually large price values
  • Zero-price bookings
  • Emoji and symbol input
  • Script-like string input

Assertions remain active so the report shows both observed behavior and differences from the proposed expectations.

These findings are not presented as confirmed defects. They represent validation risks or requirement questions that would require product clarification in a production project.


How to Run Locally

Prerequisites

1. Installation

Clone the repository and install dependencies locally:

git clone https://github.com/danielbxs/rb-api-test-suite
cd rb-api-test-suite
npm install

2. Running tests

Runs the stable regression suite

npm run test

3. Stable regression HTML report

Runs the suite and compiles an interactive HTML report inside the reports/ folder:

npm run test-report

4. Running the exploratory findings

This command may exit with failed assertions when the exploratory findings are reproduced. These failures are intentional and do not indicate a problem with the test framework.

npm run test-findings

5. Exploratory findings HTML report

The report is generated at reports/exploratory-findings.html.

npm run test-findings-report

6. Individual stable areas

  • Health check
npm run test-health
  • Auth
npm run test-auth
  • Crud
npm run test-crud
  • Edge cases
npm run test-edge

About

API test automation framework for the Restful-Booker API using Postman, Newman, and GitHub Actions.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors