A robust, enterprise-grade automated API testing framework designed to validate the backend API services of the BenchTalents Terminal platform. Built using Python, Requests, and Pytest, this suite contains extensive positive, negative, and security-focused test assertions across 21 distinct functional modules to ensure high-reliability endpoint integrations and database transactions.
BenchTalents_API_Automation_Portfolio/
├── config/
│ ├── __init__.py
│ └── settings.py # Centralized settings & dynamic environment config
├── tests/
│ ├── conftest.py # Root fixtures (reusable session setup, auth token caching)
│ ├── admin_crm/ # Admin CRM endpoint validation
│ ├── admin_graphql/ # GraphQL schema & security validation
│ ├── auth/ # Authentication & Login workflows
│ ├── bench_management/ # Bench list configurations
│ ├── bench_talents/ # Talent profiles, saving, and updates
│ ├── billing/ # Stripe integration & invoice workflows
│ ├── billing_webhooks/ # Stripe billing webhooks validation
│ ├── chat/ # Real-time chat & message APIs
│ ├── companies/ # Company profiles & invites
│ ├── cron_jobs/ # Threshold checks & system crons
│ ├── dashboard/ # Dashboard stats aggregation
│ ├── integration/ # E2E system integration flows
│ ├── job_listings/ # Job posting and searching APIs
│ ├── submissions/ # E2E Bench Talent submission pipeline
│ ├── support/ # Client support tickets APIs
│ └── [other modules...] # Comprehensive coverage across 21 directories
├── pytest.ini # Pytest configurations, logs formatting, and custom markers
├── requirements.txt # Project package dependencies
├── developer_bug_report.md # Standardized defect logging (critical, security, and schema)
├── failure_details.md # Complete bug tracebacks and payload details
├── Employment Exchange - Bench Talent Agents.postman_collection.json # Ready-to-import Postman collections
└── Employment Exchange — Bench Service API.postman_collection.json # Ready-to-import Postman collections
- Dynamic Authentication Caching: Session-scoped Pytest fixtures handle authenticating and caching JWT
Access-TokenandId-Tokenparameters, preventing redundant authorization requests and reducing overall execution time. - Automatic Retries for Rate Limits: The Requests HTTP client is wrapped with custom
urllib3retry adapters that automatically intercept rate-limiting HTTP responses (429 Too Many Requests) and server-side errors (502/503/504) with an exponential backoff strategy. - Centralized Environment Configurations: Configuration settings are handled through Python environment variables using
load_dotenvwith secure, standard placeholders for local development. - Postman Collection Integrations: Includes two fully configured, production-ready Postman Collections mapping the API routes, complete with environment variables for collection runners.
- Standardized Defect Logging: Documented defects with full API payload traces, status code analysis, and clear logs in the attached bug report files.
The suite covers all core microservice sub-domains on the platform:
| Core Module | Total Test Scenarios | Key Endpoints Validated |
|---|---|---|
| Auth | Positive, Negative, Security | /auth/login, /auth/refresh-token, user registration |
| Bench Talents | Complete Profile Management | /bench/talents/list, /bench/talents/add, /bench/talents/update |
| Job Listings | Employer Job Management | /jobs/create, /jobs/list, /jobs/search, /jobs/status |
| Submissions Pipeline | Candidate Submissions | /submissions/apply, /submissions/pipeline/stats, status changes |
| Chat Module | Real-time Messaging | /chat/conversations/create, /chat/messages/send, history |
| Billing & Payments | Stripe & Billing Plans | /billing/plans/list, /billing/subscribe, /webhooks/stripe |
| Admin & CRM | Internal CRM Operations | /admin/crm/logs, /admin/graphql/query (GraphQL endpoint) |
| Cron & Background | Maintenance Services | /cron/evaluate-thresholds, /cron/sync-candidates |
During the framework's development and execution on target environments, several backend defects were captured, categorized, and documented. Review the detailed files:
- Developer Bug Report — Categorized defects (Critical, Security Vulnerabilities, and Schema Inconsistencies).
- Failure Details log — Raw test response bodies and request parameters.
- Security Vulnerability (GraphQL Authentication Bypass):
/admin/graphqlreturned200 OKand processed queries on unauthenticated requests. - Critical Database Crash (Overflow error): DB numeric value overflow on saving rate values (999999999) returned raw database errors inside a
500 Internal Server Error. - Authentication Leak: Auth endpoint returned distinct
404 Not Foundresponses for non-existent emails, creating a username/email enumeration risk.
- Python 3.10 or higher
- pip package manager
Clone the repository and install the dependencies:
pip install -r requirements.txtSetup a .env file in the root of the project to configure base URLs and test credentials dynamically:
BASE_URL=https://api-qa.employmentexchange.com/bench/api/v1
ADMIN_EMAIL=your_admin_email@example.com
ADMIN_PASSWORD=your_secure_password_herepytest# Run Auth module tests
pytest tests/auth/ -v
# Run Bench Talent module tests
pytest tests/bench_talents/ -v
# Run Integration/E2E workflow tests
pytest tests/integration/ -v# Run tests and generate JUnit XML report
pytest --junitxml=reports/junit-report.xml
# Run with verbose console logging and traceback details
pytest -v --tb=shortTo run the included collections:
- Open Postman.
- Click Import and select the
.jsoncollection files from the root of this project. - Configure your Postman Environment variables:
base_url:https://api-qa.employmentexchange.com/bench/api/v1token:[Your Access Token]
- Run the collections using the Postman Collection Runner or via CLI using Newman.
- Achieved 98%+ test execution stability using retry wrappers.
- Covered 100% of core APIs mapping out critical user journeys.
- Documented and reported 15+ functional and security defects to backend developers.