Skip to main content

Postman Curlections

My team has been building a new service over the last few months. Until recently all the data it needs has been ingested at startup and our focus has been on the logic that processes the data, architecture, and infrastructure.

This week we introduced a couple of new endpoints that enable the creation (through an HTTP POST) and update (PUT) of the fundamental data type (we call it a definition) that the service operates on. I picked up the task of smoke testing the first implementations.

I started out by asking the system under test to show me what it can do by using Postman to submit requests and inspecting the results. It was the kinds of things you'd imagine, including:

  • submit some definitions (of various structure, size, intent, name, identifiers, etc)
  • resubmit the same definitions (identical, sharing keys, with variations, etc)
  • retrieve the submitted definitions (using whatever endpoints exist to show some view of them)
  • compare definitions I submitted from the ones I retrieved (exact match, semantic match, etc)
  • invite the system to perform actions on the definitions (in whatever ways I can)
  • submit some broken definitions (deliberately crafted and by random edits to existing definitions)
  • compare ingested definitions submitted ones (in whatever ways I can find)
  • ...
I found a few things this way, some of which we fixed straight away and some of which need to wait for work we already have planned.

But I didn't stop there. With that groundwork I was in a position to quickly run a few experiments looking for evidence that there might be some other deeper problems. 

To help me do this, I took one of the requests as a curl snippet from Postman ...


... and pasted it into a bash script:

#!/bin/bash
curl --location 'http://localhost:4444/post' --header 'Content-Type: application/json' --data '{ "some": "json" }'

I ran the script to check that it returned the same results as the request in Postman. It did, and so now I had  the beginnings of an ad hoc test rig.

The first experiment was to simply loop the request. I was interested to know what happened if I repeated a request at a fast rate:

#!/bin/bash
for i in {1..3}
do
    curl --location 'http://localhost:4444/post' --header 'Content-Type: application/json' --data '{ "some": "json" }'
done 

Depending on the request I was using this might be legitimately result in the same or different responses. Note that my rig was not checking results, just generating data for me to review.

As it happened, the responses were sometimes large and difficult to interpret, and the data that curl reports was also being printed to the console. So I told curl to be quiet, filtered to just a significant field in the payload using jq, and made the loop run more than three times:

#!/bin/bash
for i in {1..1000}
do
    curl --silent --location 'http://localhost:4444/post' --header 'Content-Type: application/json' --data '{ "some": "json" }' | jq .json
done

With an easier way to review, I could not see an obvious issue so I thought I'd retry with some of the definitions I prepared earlier by changing the script to loop over a directory of JSON files:

#!/bin/bash
for data in definitions/*.json
do
    curl --silent --location 'http://localhost:4444/post' --header 'Content-Type: application/json' -d @$data | jq .json
done

Now it became more important to see the full response again, so I stopped filtering to a single field and instead archived the whole response to a file which I could inspect at my leisure. You can see here that I simply dumped the response body to a file with the same name as the source data, suffixed with .response

#!/bin/bash
for data in definitions/*.json
do
    curl --silent --location 'http://localhost:4444/post' --header 'Content-Type: application/json' -d @$data -o $data.response
done

That's cheap and cheerful. but convenient and sufficient for this kind of exploration. I didn't know where I was going next: each of these steps, and what I found, and what I'd learned up to that point, informed the next experiment.

I was interested to see whether there might be any timing concerns. The definitions had various properties that might cause the server to do different amounts of work, so I asked for the total time for each request to be reported:

#!/bin/bash
for data in definitions/*.json
do
    curl -w "%{time_total}" --silent --location 'http://localhost:4444/post' --header 'Content-Type: application/json' -d @$data -o $data.response
    echo ""
done

That was fine, but I couldn't tell which file had which timings, so I tweaked the script a little for presentation. This version dumps a comma-separated pair of file and timing:

#!/bin/bash
for data in definitions/*.json
do
    time=`curl -w "%{time_total}" --silent --location 'http://localhost:4444/post' --header 'Content-Type: application/json' -d @$data -o $data.response`
    echo $data,$time
done

And then it was only a small step to see if the timings were consistent over time, by putting the whole thing in an outer loop:

#!/bin/bash
for i in {1..100}
do
    for data in definitions/*.json
    do 
        time=`curl -w "%{time_total}" --silent --location 'http://localhost:4444/post' -d @$data -o $data.response`
        echo $data, $time
    done
done 

I took the data that was printed to the console and plotted it as a chart using a Google spreadsheet.

Next, I tried a quick concurrency test. It simply tried to submit two requests at the same time, using the ampersand character to make the calls non-blocking, and then fetch the data to see what the service stored.

#!/bin/bash
curl --silent --location 'http://localhost:4444/post' --header 'Content-Type: application/json' --data '{ "some": "1" }' &
curl --silent --location 'http://localhost:4444/post' --header 'Content-Type: application/json' --data '{ "some": "2" }' &

sleep 1
curl --location 'http://localhost:4444/get' 

Notice that I made the submitted data slightly different so that I could tell which request, if either, was accepted by the service.

As you can see, there's not so much going on here in terms of HTTP or programming expertise (Postman and bash and several headfuls of curl are taking care of this) and I could cover a reasonable amount of ground very cheaply, amplifying the effectiveness of the work I'd already done.

Oh yes, and I found a few more issues that we'll fix shortly.

This is the kind of exploration with automation that I do a lot. I have a question and I wonder what is available, in terms of data or tools, that could help me to get the answer or some idea of whether the question is worth pursuing further. 

I'll often take a single example from somewhere, make variants of it, repeat them in different permutations or orders, inspect the result, identify interesting behaviours, and then ask another question.

I've found it really powerful over the years.
Image: Larissa Megale

Comments

Popular posts from this blog

Meet Me Halfway?

  The Association for Software Testing is crowd-sourcing a book,  Navigating the World as a Context-Driven Tester , which aims to provide  responses to common questions and statements about testing from a  context-driven perspective . It's being edited by  Lee Hawkins  who is  posing questions on  Twitter ,   LinkedIn , Mastodon , Slack , and the AST  mailing list  and then collating the replies, focusing on practice over theory. I've decided to  contribute  by answering briefly, and without a lot of editing or crafting, by imagining that I'm speaking to someone in software development who's acting in good faith, cares about their work and mine, but doesn't have much visibility of what testing can be. Perhaps you'd like to join me?   --00-- "Stop answering my questions with questions." Sure, I can do that. In return, please stop asking me questions so open to interpretation that any answ...

Can Code, Can't Code, Is Useful

The Association for Software Testing is crowd-sourcing a book,  Navigating the World as a Context-Driven Tester , which aims to provide  responses to common questions and statements about testing from a  context-driven perspective . It's being edited by  Lee Hawkins  who is  posing questions on  Twitter ,   LinkedIn , Mastodon , Slack , and the AST  mailing list  and then collating the replies, focusing on practice over theory. I've decided to  contribute  by answering briefly, and without a lot of editing or crafting, by imagining that I'm speaking to someone in software development who's acting in good faith, cares about their work and mine, but doesn't have much visibility of what testing can be. Perhaps you'd like to join me?   --00-- "If testers can’t code, they’re of no use to us" My first reaction is to wonder what you expect from your testers. I am immediately interested ...

The Best Programmer Dan Knows

  I was pairing with my friend Vernon at work last week, on a tool I've been developing. He was smiling broadly as I talked him through what I'd done because we've been here before. The tool facilitates a task that's time-consuming, inefficient, error-prone, tiresome, and important to get right. Vern knows that those kinds of factors trigger me to change or build something, and that's why he was struggling not to laugh out loud. He held himself together and asked a bunch of sensible questions about the need, the desired outcome, and the approach I'd taken. Then he mentioned a talk by Daniel Terhorst-North, called The Best Programmer I Know, and said that much of it paralleled what he sees me doing. It was my turn to laugh then, because I am not a good programmer, and I thought he knew that already. What I do accept, though, is that I am focussed on the value that programs can give, and getting some of that value as early as possible. He sent me a link to the ta...

Beginning Sketchnoting

In September 2017 I attended  Ian Johnson 's visual note-taking workshop at  DDD East Anglia . For the rest of the day I made sketchnotes, including during Karo Stoltzenburg 's talk on exploratory testing for developers  (sketch below), and since then I've been doing it on a regular basis. Karo recently asked whether I'd do a Team Eating (the Linguamatics brown bag lunch thing) on sketchnoting. I did, and this post captures some of what I said. Beginning sketchnoting, then. There's two sides to that: I still regard myself as a beginner at it, and today I'll give you some encouragement and some tips based on my experience, to begin sketchnoting for yourselves. I spend an enormous amount of time in situations where I find it helpful to take notes: testing, talking to colleagues about a problem, reading, 1-1 meetings, project meetings, workshops, conferences, and, and, and, and I could go on. I've long been interested in the approaches I've evol...

Not Strictly for the Birds

  One of my chores takes me outside early in the morning and, if I time it right, I get to hear a charming chorus of birdsong from the trees in the gardens down our road, a relaxing layered soundscape of tuneful calls, chatter, and chirrupping. Interestingly, although I can tell from the number and variety of trills that there must be a large number of birds around, they are tricky to spot. I have found that by staring loosely at something, such as the silhouette of a tree's crown against the slowly brightening sky, I see more birds out of the corner of my eye than if I scan to look for them. The reason seems to be that my peripheral vision picks up movement against the wider background that direct inspection can miss. An optometrist I am not, but I do find myself staring at data a great deal, seeking relationships, patterns, or gaps. I idly wondered whether, if I filled my visual field with data, I might be able to exploit my peripheral vision in that quest. I have a wide monito...

ChatGPTesters

The Association for Software Testing is crowd-sourcing a book,  Navigating the World as a Context-Driven Tester , which aims to provide  responses to common questions and statements about testing from a  context-driven perspective . It's being edited by  Lee Hawkins  who is  posing questions on  Twitter ,   LinkedIn , Mastodon , Slack , and the AST  mailing list  and then collating the replies, focusing on practice over theory. I've decided to  contribute  by answering briefly, and without a lot of editing or crafting, by imagining that I'm speaking to someone in software development who's acting in good faith, cares about their work and mine, but doesn't have much visibility of what testing can be. Perhaps you'd like to join me?   --00--  "Why don’t we replace the testers with AI?" We have a good relationship so I feel safe telling you that my instinctive reaction, as a member of the T...

Vanilla Flavour Testing

I have been pairing with a new developer colleague recently. In our last session he asked me "is this normal testing?" saying that he'd never seen anything like it anywhere else that he'd worked. We finished the task we were on and then chatted about his question for a few minutes. This is a short summary of what I said. I would describe myself as context-driven . I don't take the same approach to testing every time, except in a meta way. I try to understand the important questions, who they are important to, and what the constraints on the work are. With that knowledge I look for productive, pragmatic, ways to explore whatever we're looking at to uncover valuable information or find a way to move on. I write test notes as I work in a format that I have found to be useful to me, colleagues, and stakeholders. For me, the notes should clearly state the mission and give a tl;dr summary of the findings and I like them to be public while I'm working not just w...

Build Quality

  The Association for Software Testing is crowd-sourcing a book,  Navigating the World as a Context-Driven Tester , which aims to provide  responses to common questions and statements about testing from a  context-driven perspective . It's being edited by  Lee Hawkins  who is  posing questions on  Twitter ,   LinkedIn , Mastodon , Slack , and the AST  mailing list  and then collating the replies, focusing on practice over theory. I've decided to  contribute  by answering briefly, and without a lot of editing or crafting, by imagining that I'm speaking to someone in software development who's acting in good faith, cares about their work and mine, but doesn't have much visibility of what testing can be. Perhaps you'd like to join me?   --00-- "When the build is green, the product is of sufficient quality to release" An interesting take, and one I wouldn't agree with in gener...

Express, Listen, and Field

Last weekend I participated in the LLandegfan Exploratory Workshop on Testing (LLEWT) 2024, a peer conference in a small parish hall on Anglesey, north Wales. The topic was communication and I shared my sketchnotes and a mind map from the day a few days ago. This post summarises my experience report.  Express, Listen, and Field Just about the most hands-on, practical, and valuable training I have ever done was on assertiveness with a local Cambridge coach, Laura Dain . In it she introduced Express, Listen, and Field (ELF), distilled from her experience across many years in the women’s movement, business, and academia.  ELF: say your key message clearly and calmly, actively listen to the response, and then focus only on what is relevant to your needs. I blogged a little about it back in 2017 and I've been using it ever since. Assertiveness In a previous role, I was the manager of a test team and organised training for the whole ...