🏫 The School›🏢 APIs›16 · 🧪 API test चा प्रत्येक प्रकार — काउंटर test करण्याच्या नऊ पद्धती
🖼️ See the drawing + lab 🏠 Course home 🌿 Branch on GitHub ✏️ View source
🖼️ आकृती आणि labThe drawing + lab पूर्ण पानावर उघडा ↗Open full page ↗

16 · 🧪 API test चा प्रत्येक प्रकार — काउंटर test करण्याच्या नऊ पद्धती

📦 या ब्रँचमध्ये काय आहे

धडे 01–16 — पूर्ण कोर्स. api/ मध्ये काहीही नवीन नाही: हा धडा आधीपासून असलेले कसे वापरायचे याबद्दल आहे.

🧒 5 वर्षांच्या मुलाला समजावल्यासारखे

शाळा उघडण्याआधी तुम्ही प्रत्येक दिव्याचे बटण एकदा दाबून पाहता (smoke). मग तुम्ही नियमपुस्तिकेतला प्रत्येक नियम तपासता (functional), पूर्ण दिवसभर इमारतीतून फिरून पाहता (integration), आजची इमारत कालच्या फोटोशी जुळवता (regression), अपेक्षित गर्दीने सभागृह भरता (load), मग त्याच्या दहापट गर्दी आणून काय मोडते आणि ते पुन्हा सावरते का ते पाहता (stress), प्रत्येक दार चुकीच्या चावीने उघडून पाहता (security), विद्यार्थिनी वापरेल तसा सूचना फलक वापरता (UI), आणि शेवटी काउंटर दचकेपर्यंत त्याला निरर्थक गोष्टी भरवता (fuzz).

🗺️ आकृती

flowchart LR
  S[smoke · every push] --> F[functional · every rule] --> I[integration · the stories] --> R[regression · diff the answers]
  R --> L[load · before launch] --> SE[security · before public] --> FZ[fuzz · touch a parser] --> ST[stress · the failure mode] --> U[UI · a few golden paths]

❓ काय

प्रकार काय विचारतो या काउंटरवर
Smoke मुळात काही मोडते का? bash api/smoke_test.sh — 12 तपासण्या, 30 सेकंद
Functional spec जे सांगते ते हे करते का? प्रत्येक नियमासाठी एक case: duplicate email → 409, key नाही → 401, एकच error shape
Integration खऱ्या शेजाऱ्यांसह, एकामागून एक अनेक calls चालतात का? enrol → read → update → delete → 404, webhook receiver चालू ठेवून
Regression बदलामुळे आधी चालणारे मोडले का? प्रत्येक उत्तराचा JSON नोंदवा; जुना build विरुद्ध नवा diff करा
Load क्षमता किती आहे? अपेक्षित traffic वर k6 / hey; p95, errors, 429s पाहा
Stress ते कसे मोडते, आणि पुन्हा सावरते का? 10× load; अपयश सभ्य 429s आहेत की crashes?
Security प्रत्येक दार, प्रत्येक कुलूप key नाही, चुकीची key, प्रत्येक field मध्ये injection, 1000 requests; logs तपासा
UI सूचना फलकाद्वारे UI शाळेचा फलक या API वर enrol form भरतो
Fuzz त्याला निरर्थक गोष्टी भरवा रिकामे, प्रचंड, चुकीचे types, unicode — कोणताही 500 किंवा अडकणे म्हणजे एक शोध

🤔 का

प्रत्येक प्रकार अशा bugs चा वर्ग पकडतो जो इतर पकडू शकत नाहीत. Smoke "ते सुरूच होत नाही" पकडतो; functional "नियम चुकीचा आहे" पकडतो; integration "तुकड्यांचे एकमत नाही" पकडतो; regression "गेल्या मंगळवारी आपण ते मोडले" पकडतो; load आणि stress "ते कोसळते" पकडतात; security "कोणीही करू शकतो" पकडतो; fuzz "parser input वर विश्वास ठेवतो" पकडतो.

🔧 कसे (या repo मध्ये)

api/ मधली प्रत्येक script एक छोटी test आहे: smoke_test.sh प्रत्येक धड्यासाठी एक गोष्ट तपासतो, methods_demo.sh तीन शब्द assert करतो, auth_client.py प्रत्येक 401 आणि 403 assert करतो, types_client.py तारेवरचे सहा आकार assert करतो. CI/CD शाळा प्रत्येक push वर smoke test चालवते; बाकीच्या सवयी काउंटर वाढेल तशा तुम्ही जोडता.

🧪 करून पाहा

python3 api/school_api.py &
bash api/smoke_test.sh                                                                  # smoke
for i in $(seq 1 40); do curl -s -o /dev/null -w '%{http_code} ' http://127.0.0.1:8080/v1/health; done; echo   # a tiny load test: watch the 429s begin
curl -s -X POST http://127.0.0.1:8080/v1/students -H 'X-API-Key: hall-pass-123' -H 'Content-Type: application/json' \
     -d '{"name":"","class":"9Z","grade":"Z"}'                                          # fuzz by hand: a 400 with problems, never a 500

✅ तपासा — तुम्हाला काय दिसायला हवे

Smoke test नावे दिलेले 12 blocks छापतो आणि एकही ❌ नाही. Load loop 200s छापतो, जे bucket रिकामी झाल्यावर 429s मध्ये बदलतात (धडा 10). Fuzz request तीन problems सह 400 उत्तर देते — काउंटर सभ्यपणे दचकतो, आणि तेच योग्य उत्तर आहे.

🏁 तुम्ही आत्ताच काय सिद्ध केले

तुम्ही खऱ्या काउंटरवर testing च्या नऊपैकी तीन प्रकार चालवले, आणि उरलेल्या सहापैकी पुढे कोणते जोडायचे आणि का हे तुम्हाला माहीत आहे: प्रत्येक push वर smoke, प्रत्येक नियमासाठी functional, कथांसाठी integration, diff करून regression, launch आधी load, public होण्याआधी security, parser ला हात लावल्यावर fuzz, अपयशाची पद्धत समजण्यासाठी stress, काही सोनेरी मार्गांसाठी UI.

⚠️ नेहमीच्या चुका

🏭 प्रत्यक्ष वापरात हे का महत्त्वाचे: pyramid म्हणजे अनेक functional, काही integration, थोडे end-to-end — आणि प्रत्येक deploy वर smoke. Regression वगळणाऱ्या टीम्स तोच bug दोनदा ship करतात; fuzz वगळणाऱ्या टीम्स एका emoji साठी 500 ship करतात.

🎓 कोर्स पूर्ण झाला

सोळा धडे: बारा धड्यांत बांधलेला एक काउंटर, आणि बाकी सगळ्याला जागा देणारे चार संपूर्ण नकाशे. अभ्यास आराखडा त्यांना खूण करतो; quiz मध्ये धडे 13–16 साठी भाग 3 आहे; School portal मध्ये प्रमाणपत्र आहे.

16 · 🧪 Every kind of API test — nine ways to test a counter

📦 What's in this branch

Lessons 01–16 — the whole course. Nothing new in api/: this lesson is about how to use what is already there.

🧒 Explain like I'm 5

Before the school opens you flick every light switch once (smoke). Then you check every rule in the handbook (functional), walk a whole day through the building (integration), compare today's building with yesterday's photo (regression), fill the hall with the expected crowd (load), then ten times that crowd to see what breaks and whether it recovers (stress), try every door with the wrong key (security), use the notice board the way a student would (UI), and finally feed the counter nonsense until it flinches (fuzz).

🗺️ Diagram

flowchart LR
  S[smoke · every push] --> F[functional · every rule] --> I[integration · the stories] --> R[regression · diff the answers]
  R --> L[load · before launch] --> SE[security · before public] --> FZ[fuzz · touch a parser] --> ST[stress · the failure mode] --> U[UI · a few golden paths]

❓ What

Type Asks Against this counter
Smoke does anything break at all? bash api/smoke_test.sh — 12 checks, 30 seconds
Functional does it do what the spec says? a case per rule: duplicate email → 409, missing key → 401, one error shape
Integration do several calls in a row work, with real neighbours? enrol → read → update → delete → 404, with the webhook receiver running
Regression did the change break what worked? record the JSON of every answer; diff old build vs new
Load what is the capacity? k6 / hey at expected traffic; watch p95, errors, the 429s
Stress how does it break, and does it recover? 10× the load; are the failures polite 429s or crashes?
Security every door, every lock no key, wrong key, injection in every field, 1000 requests; check the logs
UI through the notice board the UI school's board fills the enrol form against this API
Fuzz feed it nonsense empty, huge, wrong types, unicode — any 500 or hang is a finding

🤔 Why

Each type catches a class of bug the others cannot. Smoke catches "it does not start"; functional catches "the rule is wrong"; integration catches "the pieces disagree"; regression catches "we broke it last Tuesday"; load and stress catch "it falls over"; security catches "anyone can"; fuzz catches "the parser trusts input".

🔧 How (in this repo)

Every script in api/ is a small test: smoke_test.sh checks one thing per lesson, methods_demo.sh asserts the three words, auth_client.py asserts every 401 and 403, types_client.py asserts six wire shapes. The CI/CD school runs the smoke test on every push; the others are the habits you add as the counter grows.

🧪 Try it

python3 api/school_api.py &
bash api/smoke_test.sh                                                                  # smoke
for i in $(seq 1 40); do curl -s -o /dev/null -w '%{http_code} ' http://127.0.0.1:8080/v1/health; done; echo   # a tiny load test: watch the 429s begin
curl -s -X POST http://127.0.0.1:8080/v1/students -H 'X-API-Key: hall-pass-123' -H 'Content-Type: application/json' \
     -d '{"name":"","class":"9Z","grade":"Z"}'                                          # fuzz by hand: a 400 with problems, never a 500

✅ Verify — what you should see

The smoke test prints 12 labelled blocks and no ❌. The load loop prints 200s that turn into 429s after the bucket empties (lesson 10). The fuzz request answers 400 with three problems — the counter flinching politely, which is the correct answer.

🏁 What you just proved

You ran three of the nine testing types against a real counter, and you know which of the other six to add next and why: smoke on every push, functional for every rule, integration for the stories, regression by diffing, load before launch, security before public, fuzz when you touch a parser, stress to learn the failure mode, UI for a few golden paths.

⚠️ Common mistakes

🏭 Why this matters in production: the pyramid is many functional, some integration, few end-to-end — plus smoke on every deploy. Teams that skip regression ship the same bug twice; teams that skip fuzz ship a 500 for an emoji.

🎓 The course is complete

Sixteen lessons: a counter built in twelve, and the four full maps that place everything else. The study plan ticks them off; the quiz has a Part 3 for lessons 13–16; the School portal has the certificate.

← Previousapi typesNext →performance monitoring

This page is the lesson's README from the lesson-16-testing-types branch, shown here so the whole School stays on one site. Code files open on GitHub at the same branch.