QA Engineer Professional · Проєкт 2
API contract test portfolio
Створіть portfolio-safe API testing artifact для власного, demo або письмово дозволеного sandbox. Покажіть contract reading, traceable design, authorization judgment, reproducible runner і чесні limitations.
Обов’язкові deliverables
| Артефакт | Мінімум |
|---|---|
| Contract inventory | Version/hash, server/scope, 5+ operations, parameters/bodies/responses/security та gaps. |
| 20+ traceable cases | Positive, negative, boundary, schema/error, authorization, workflow, pagination/concurrency. |
| Executable collection | Environment placeholders, assertions, generated synthetic IDs, preflight, cleanup; no tokens. |
| Authorization matrix | Actors×objects×operations/properties, zero-effect oracle та safe evidence. |
| API report | Run summary, findings, defect/risk evidence, coverage, limitations і release recommendation. |
Безпека й чесність
- Тільки власний, intentionally vulnerable lab або письмово дозволений sandbox; production load/exploitation заборонені.
- Не передавайте tokens, cookies, client secrets, real emails, customer IDs або private specs.
- Authorization test зупиняється після мінімального доказу; не збирайте чужі data.
- Rate/concurrency/size cases мають письмові limits і stop rule.
- Simulated/stubbed outcomes позначайте; не видавайте mock run за production evidence.
- HTTPS portfolio відкривається reviewer без password, але не містить active credentials.
Рубрика — 100 балів
Прийнято: від 80/100 після приватного review SEOWORK.
Перед поданням
- Замініть demo rows лише дозволеними observations або чесно залиште synthetic case study.
- Запустіть collection двічі на clean namespace й підтвердьте cleanup.
- Перевірте schemas, links, report та redaction у приватному вікні.
- Опублікуйте один HTTPS artifact із README, без active credentials.
Офіційна основа
Подання роботи на перевірку
Передайте HTTPS-посилання на папку або репозиторій із доступом для перегляду. Не додавайте паролі, API-ключі, персональні дані клієнтів чи production-вивантаження.
- Versioned API inventory та OpenAPI contract baseline з traceability і gaps
- Щонайменше 20 positive, negative, boundary, schema та error cases
- Authorization matrix для actors, objects, properties і functions із zero-effect oracles
- Reproducible collection для workflow, pagination та concurrency із synthetic data, preflight і cleanup
- Portfolio-safe HTTPS API report без PII, secrets або недозволених матеріалів
- Contract, inventory and traceability — 20
- Test design, schemas and error oracles — 20
- Authentication, authorization and abuse controls — 20
- Workflow, automation, determinism and cleanup — 20
- Evidence, limitations, safety and delivery — 20