Skip to main content

Few popular authentications in Rest Assured

There are many types of authentication or some people prefer to call it authentication protocols in Rest Assured but few popular ones are:
Basic Authentication, OAuth 1 and OAuth 2
The basic authentication requires the users to send user id and a password like:
Response response =
given()
.auth()
.basic("username", "password")
.when()
.get("http://localhost:9090/sample/id/900");

In the case of OAuth 1.0, we need to send a Consumer Key, Secret, Access Token and Token Secret to access a secured resource:
Response response =
given()
.contentType("application/JSON")
 .auth()
 .oauth(consumerKey, consumerSecret, accessToken, tokenSecret)
 .formParam("paramKey", "paramValue").
 .when()
.post("http://localhost:9090/sample/id/880");

In the case of OAuth 2.0, the access token is required to access a secured resource:
First, you need to extract access token using authorization URL with the help of ClientId, ClientSecret, grant_type, and scope of the request like:
Response response =
given()
.auth()
.basic(clientId, clientSecret)
.formParam("grant_type", "client_credentials")
.formParam("scope", scope)
.when()
.post(/sample/id/900);

JSONObject jsonObj = new JSONObject(response.getBody().asString());
String accessToken = jsonObj.get("access_token").toString();

OR using ClientId, ClientSecret, username, password, and scope of the request like:
Response response =
given()
.auth()
.basic(clientId, clientSecret)  
.formParam("grant_type", "password")
.formParam("username", username)
.formParam("password", password)
.formParam("scope", scope)
.when()
 .post(/sample/id/900);

JSONObject jsonObj = new JSONObject(response.getBody().asString());
String accessToken = jsonObj.get("access_token").toString();

Then you can consume that accessToken in oauth2 like:
Response response =
given()
.auth()
.oauth2(accessToken
.contentType("application/json")
.body(JSONString)
.when()
.post("/sample/id/890");
Note* In order to use OAuth1 and OAuth2 for query parameter signing, you need to add Scribe dependency (scribejava-apis) in your pom.xml along with rest Assured (io.rest-assured) dependency especially if you are using an older version of REST Assured i.e. <2.5.0

Comments

Popular posts from this blog

Clipboardy: Node.js library

 Clipboardy is a popular Node.js library that provides a cross-platform solution for interacting with the system clipboard. It supports both synchronous and asynchronous operations, and it can be used to copy, paste, and read the clipboard contents. Features of Clipboardy: 1. Cross-platform compatibility: It works on macOS, Windows, Linux, OpenBSD, FreeBSD, Android with Termux, and modern browsers. 2. Synchronous and asynchronous operations: It provides both synchronous and asynchronous methods for clipboard operations, making it suitable for a variety of use cases. 3. Copy, paste, and read operations: It supports copying, pasting, and reading the clipboard contents, making it a versatile tool for interacting with the clipboard. 4. Promise-based API: It is an asynchronous method that returns promises, making it easy to handle asynchronous operations in a clean and concise way. 5. Easy to use: It has a simple and intuitive API that is easy to learn and use. How to Use Clipboardy: To...

ARIA Snapshot in Playwright

  What is an ARIA Snapshot in Playwright? An  ARIA snapshot  in Playwright is a structured representation of a page’s  accessibility tree , which is used by assistive technologies (e.g., screen readers) to interpret the content of a web page. This snapshot helps verify if elements have the correct  roles, names, and properties  required for accessibility. Playwright provides the page.accessibility.snapshot() API to capture this accessibility tree at any given moment during test execution. How Does ARIA Work? ARIA ( Accessible Rich Internet Applications ) is a set of attributes that help improve accessibility by defining roles, states, and properties for elements that are not natively accessible. Example: In this case, the aria-label ensures that screen readers identify the button as “Submit Form.” How to Use ARIA Snapshots in Playwright? Playwright’s  accessibility.snapshot()   method retrieves the  accessible structure  of the page. Ex...

Bruno vs Postman: Which API Client Should You Choose?

  As API testing becomes more central to modern software development, the tools we use to test, automate, and debug APIs can make a big difference. For years, Postman has been the go-to API client for developers and testers alike. But now, Bruno , a relatively new open-source API client, is making waves in the community. Let’s break down how Bruno compares to Postman and why you might consider switching or using both depending on your use case. ✨ What is Bruno? Bruno is an open-source, Git-friendly API client built for developers and testers who prefer simplicity, speed, and local-first development. It stores your API collections as plain text in your repo, making it easy to version, review, and collaborate on API definitions. 🌟 What is Postman? Postman is a full-fledged API platform that offers everything from API testing, documentation, and automation to mock servers and monitoring. It comes with a polished UI, robust integration, and support for collaborati...