DEV Community

Cover image for API Testing Rule 5/10: Every Collection Endpoint Must Have Bounded Results
Liudas
Liudas

Posted on

API Testing Rule 5/10: Every Collection Endpoint Must Have Bounded Results

GET /customers may work perfectly with 100 records. But what happens when the dataset grows to one million?

Pagination alone is not enough. Collection endpoints should enforce a maximum page size and predictable defaults. API testing should verify what happens when pagination parameters are omitted, extremely large limits are requested, complex filtering and sorting are combined with pagination, or large collections are retrieved repeatedly.

Without server-enforced limits, a single valid request can consume excessive database, memory, network, and client resources. An endpoint that returns unbounded results is a scalability and reliability defect waiting to become a production incident.

In the complete white paper, we explain how to test pagination, maximum page sizes, cursor-based navigation, filtering, sorting, performance under large datasets, and protection against excessive requests.

Read the complete white paper: https://qaontime.com/research/the-power-of-ten-rules-for-testing-http-apis.html

Automation Before Automation.

Top comments (0)