Schemathesis v4.30.1 ━━━━━━━━━━━━━━━━━━━━ ✅ Loaded specification from http://0.0.0.0:43437/ (in 0.13s) Base URL: http://0.0.0.0:43437 Specification: Open API 2.0 Operations: 26 selected / 26 total Configuration: /home/stranger6667/data/programming/workbench/target s/postgrest/schemathesis.toml ✅ API capabilities: Supports NULL byte in headers: ✓ Accepts backslash and control characters in URL paths: ✓ ⏭ Examples (in 0.01s) ⏭ 26 skipped ❌ Coverage (in 3.44s) ❌ 26 failed ❌ Fuzzing (in 1650.61s) ❌ 26 failed ❌ Stateful (in 1945.74s) Scenarios: 65875 API Links: 24 covered / 33 selected / 33 total ✅ 62419 passed ❌ 3456 failed =================================== FAILURES =================================== _______________________________ DELETE /authors ________________________________ 1. Test Case ID: JpAcRA - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/authors?id=&name=&born=&country=&website=' 2. Test Case ID: ris36u - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X DELETE -H 'Prefer: return=representation' 'http://0.0.0.0:43437/authors?id=&name=&born=&country=&website=' 3. Test Case ID: 6eykL2 - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43437/authors 4. Test Case ID: 060dXj - Undocumented HTTP status code Received: 200 Documented: 204 [200] OK: `[]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Prefer: return=representation' http://0.0.0.0:43437/authors 5. Test Case ID: bdYwJO - Undocumented HTTP status code Received: 401 Documented: 204 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table authors"}` Reproduce with: curl -X DELETE http://0.0.0.0:43437/authors 6. Test Case ID: HYFDe9 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Prefer` in header - violates `enum` at /properties/Prefer [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Prefer;' http://0.0.0.0:43437/authors ______________________________ DELETE /book_tags _______________________________ 1. Test Case ID: NZyxTS - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/book_tags?book_id=&tag_id=' 2. Test Case ID: cv8VJK - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X DELETE -H 'Prefer: return=representation' 'http://0.0.0.0:43437/book_tags?book_id=&tag_id=' 3. Test Case ID: yOawua - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43437/book_tags 4. Test Case ID: 2HqtOz - Undocumented HTTP status code Received: 401 Documented: 204 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table book_tags"}` Reproduce with: curl -X DELETE http://0.0.0.0:43437/book_tags 5. Test Case ID: 453wH6 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Prefer` in header - violates `enum` at /properties/Prefer [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Prefer;' http://0.0.0.0:43437/book_tags 6. Test Case ID: TRCSNC - Undocumented HTTP status code Received: 200 Documented: 204 [200] OK: `[]` Reproduce with: curl -X DELETE -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' http://0.0.0.0:43437/book_tags ________________________________ DELETE /books _________________________________ 1. Test Case ID: L5zFtc - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/books?id=&author_id=%5BFiltered%5D&title=&isbn=&genre=&pages=&price=&published_at=&keywords=%5BFiltered%5D&details=&in_print=' 2. Test Case ID: 4LvqY1 - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X DELETE -H 'Prefer: return=representation' 'http://0.0.0.0:43437/books?id=&author_id=%5BFiltered%5D&title=&isbn=&genre=&pages=&price=&published_at=&keywords=%5BFiltered%5D&details=&in_print=' 3. Test Case ID: Y08jzd - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43437/books 4. Test Case ID: 6pSOJg - Undocumented HTTP status code Received: 401 Documented: 204 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table books"}` Reproduce with: curl -X DELETE http://0.0.0.0:43437/books 5. Test Case ID: q2EAsV - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Prefer` in header - violates `enum` at /properties/Prefer [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Prefer;' http://0.0.0.0:43437/books 6. Test Case ID: eipHWJ - Undocumented HTTP status code Received: 200 Documented: 204 [200] OK: `[]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Prefer: return=representation' http://0.0.0.0:43437/books ________________________________ DELETE /loans _________________________________ 1. Test Case ID: ALPWcn - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/loans?id=&book_id=&borrower=&period=&returned=' 2. Test Case ID: bEGHx2 - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X DELETE -H 'Prefer: return=representation' 'http://0.0.0.0:43437/loans?id=&book_id=&borrower=&period=&returned=' 3. Test Case ID: PCLwgP - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43437/loans 4. Test Case ID: AAkSTh - Undocumented HTTP status code Received: 401 Documented: 204 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table loans"}` Reproduce with: curl -X DELETE http://0.0.0.0:43437/loans 5. Test Case ID: 9zbphf - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Prefer` in header - violates `enum` at /properties/Prefer [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Prefer;' http://0.0.0.0:43437/loans 6. Test Case ID: 5gLc1n - Undocumented HTTP status code Received: 200 Documented: 204 [200] OK: `[]` Reproduce with: curl -X DELETE -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' http://0.0.0.0:43437/loans _________________________________ DELETE /tags _________________________________ 1. Test Case ID: LLULiE - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/tags?id=&name=' 2. Test Case ID: u9sV7A - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X DELETE -H 'Prefer: return=representation' 'http://0.0.0.0:43437/tags?id=&name=' 3. Test Case ID: Vzaie3 - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:43437/tags 4. Test Case ID: N874zL - Undocumented HTTP status code Received: 401 Documented: 204 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table tags"}` Reproduce with: curl -X DELETE http://0.0.0.0:43437/tags 5. Test Case ID: UNS0FV - Undocumented HTTP status code Received: 200 Documented: 204 [200] OK: `[]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Prefer: return=representation' http://0.0.0.0:43437/tags 6. Test Case ID: pbF4rL - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Prefer` in header - violates `enum` at /properties/Prefer [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Prefer;' http://0.0.0.0:43437/tags _________________________________ GET /authors _________________________________ 1. Test Case ID: FXwoho - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 206 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Prefer: count=none' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/authors?id=&name=&born=&country=&website=&select=&order=&offset=&limit=' 2. Test Case ID: HEFMG1 - Response violates schema null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/authors/properties/website: { "type": "string", "format": "text" } Value: null [200] OK: `[{"id":1,"name":"Ursula K. Le Guin","born":"1929-10-21","country":"US","website":null}, {"id":2,"name":"Stanislaw Lem","born":"1921-09-12","country":"PL","website":null}, {"id":0,"name":"{}","born":"2000-01-01","country":" ","website":""}]` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/authors?select=' 3. Test Case ID: rTd2IN - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /authors` [200] OK: `[{"id":1,"name":"Ursula K. Le Guin","born":"1929-10-21","country":"US","website":null}, {"id":2,"name":"Stanislaw Lem","born":"1921-09-12","country":"PL","website":null}, {"id":0,"name":"{}","born":"2000-01-01","country":" ","website":""}]` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/authors?select=' 4. Test Case ID: bdj912 - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/authors?id=&name=&born=&country=&website=&select=&order=&offset=&limit=' 5. Test Case ID: aUvucj - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Authorization` in header - violates `required` (was Authorization) [200] OK: `[{"id":1,"name":"Ursula K. Le Guin","born":"1929-10-21","country":"US","website":null}, {"id":2,"name":"Stanislaw Lem","born":"1921-09-12","country":"PL","website":null}, {"id":0,"name":"{}","born":"2000-01-01","country":" ","website":""}, {"id":-202297,"name":"=","born":"0116-01-16","country":"!\u0019","website":null}, {"id":126705155973,"name":"\u0012󄐉\u000f","born":"1921-09-12","country":" ","website":"¬󃺳¢􍗬"}, {"id":-202296,"name":"=","born":"0116-01-16","country":"!\u0019","website":null}, // Output truncated...` Reproduce with: curl -X GET http://0.0.0.0:43437/authors ________________________________ GET /book_tags ________________________________ 1. Test Case ID: y7A42U - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 206 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Prefer: count=none' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/book_tags?book_id=&tag_id=&select=&order=&offset=&limit=' 2. Test Case ID: T9yACe - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /book_tags` [200] OK: `[{"book_id":1,"tag_id":1}, {"book_id":1,"tag_id":2}, {"book_id":2,"tag_id":2}]` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/book_tags?select=' 3. Test Case ID: UB5lA2 - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/book_tags?book_id=&tag_id=&select=&order=&offset=&limit=' 4. Test Case ID: 5rhbgV - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Authorization` in header - violates `required` (was Authorization) [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43437/book_tags 5. Test Case ID: IXkyPc - Server error - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json, application/vnd.pgrst.object+json;nulls=stripped, application/vnd.pgrst.object+json, text/csv - Undocumented HTTP status code Received: 500 Documented: 200, 206 [500] Internal Server Error: `Something went wrong` Reproduce with: curl -X GET -H 'Prefer: count=none' -H $'Range: M%\xc2\x87' http://0.0.0.0:43437/book_tags __________________________________ GET /books __________________________________ 1. Test Case ID: R80721 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 206 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Prefer: count=none' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/books?id=&author_id=%5BFiltered%5D&title=&isbn=&genre=&pages=&price=&published_at=&keywords=%5BFiltered%5D&details=&in_print=&select=&order=&offset=&limit=' 2. Test Case ID: YDgv1L - Response violates schema null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/books/properties/published_at: { "type": "string", "format": "timestamp with time zone" } Value: null [200] OK: `[{"id":1,"author_id":1,"title":"The Dispossessed","isbn":"9780061054884","genre":"fiction","pages":387,"price":9.99,"published_at":null,"keywords":["anarchy","physics"],"details":{"series": "Hainish"},"in_print":true}, {"id":2,"author_id":2,"title":"Solaris","isbn":"9780156027601","genre":"science","pages":204,"price":12.50,"published_at":null,"keywords":["ocean"],"details":{},"in_print":true}]` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/books?select=' 3. Test Case ID: ZH2y0i - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /books` [200] OK: `[{"id":1,"author_id":1,"title":"The Dispossessed","isbn":"9780061054884","genre":"fiction","pages":387,"price":9.99,"published_at":null,"keywords":["anarchy","physics"],"details":{"series": "Hainish"},"in_print":true}, {"id":2,"author_id":2,"title":"Solaris","isbn":"9780156027601","genre":"science","pages":204,"price":12.50,"published_at":null,"keywords":["ocean"],"details":{},"in_print":true}]` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/books?select=' 4. Test Case ID: onFXz7 - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/books?id=&author_id=%5BFiltered%5D&title=&isbn=&genre=&pages=&price=&published_at=&keywords=%5BFiltered%5D&details=&in_print=&select=&order=&offset=&limit=' 5. Test Case ID: PthbIp - Response violates schema (3 violations) null is not of type "integer" Validated against the response schema for status code 200. Schema at /definitions/books/properties/pages: { "type": "integer", "format": "int32" } Value: null null is not of type "number" Validated against the response schema for status code 200. Schema at /definitions/books/properties/price: { "type": "number", "format": "numeric" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/books/properties/isbn: { "type": "string", "format": "text" } Value: null [200] OK: `[{"id":1,"author_id":1,"title":"The Dispossessed","isbn":"9780061054884","genre":"fiction","pages":387,"price":9.99,"published_at":null,"keywords":["anarchy","physics"],"details":{"series": "Hainish"},"in_print":true}, {"id":2,"author_id":2,"title":"Solaris","isbn":"9780156027601","genre":"science","pages":204,"price":12.50,"published_at":null,"keywords":["ocean"],"details":{},"in_print":true}, {"id":22649,"author_id":0,"title":"","isbn":null,"genre":"science","pages":null,"price":null,"published_at":nu // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43437/books 6. Test Case ID: i5Q5ji - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Authorization` in header - violates `required` (was Authorization) [200] OK: `[{"id":1,"author_id":1,"title":"The Dispossessed","isbn":"9780061054884","genre":"fiction","pages":387,"price":9.99,"published_at":null,"keywords":["anarchy","physics"],"details":{"series": "Hainish"},"in_print":true}, {"id":2,"author_id":2,"title":"Solaris","isbn":"9780156027601","genre":"science","pages":204,"price":12.50,"published_at":null,"keywords":["ocean"],"details":{},"in_print":true}, {"id":22649,"author_id":0,"title":"","isbn":null,"genre":"science","pages":null,"price":null,"published_at":nu // Output truncated...` Reproduce with: curl -X GET -H 'Range: bytes=311-1010' http://0.0.0.0:43437/books ___________________________ GET /books_with_authors ____________________________ 1. Test Case ID: vBBmeV - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 206 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Prefer: count=none' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/books_with_authors?id=&title=&genre=&price=&author=%5BFiltered%5D&select=&order=&offset=&limit=' 2. Test Case ID: G9p3z3 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /books_with_authors` [200] OK: `[{"id":1,"title":"The Dispossessed","genre":"fiction","price":9.99,"author":"Ursula K. Le Guin"}, {"id":2,"title":"Solaris","genre":"science","price":12.50,"author":"Stanislaw Lem"}]` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/books_with_authors?select=' 3. Test Case ID: dxcdk1 - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/books_with_authors?id=&title=&genre=&price=&author=%5BFiltered%5D&select=&order=&offset=&limit=' 4. Test Case ID: wzsDRr - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Authorization` in header - violates `required` (was Authorization) [200] OK: `[{"id":1,"title":"The Dispossessed","genre":"fiction","price":9.99,"author":"Ursula K. Le Guin"}, {"id":2,"title":"Solaris","genre":"science","price":12.50,"author":"Stanislaw Lem"}]` Reproduce with: curl -X GET http://0.0.0.0:43437/books_with_authors 5. Test Case ID: EEs1ST - Server error - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json, application/vnd.pgrst.object+json;nulls=stripped, application/vnd.pgrst.object+json, text/csv - Undocumented HTTP status code Received: 500 Documented: 200, 206 [500] Internal Server Error: `Something went wrong` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Range: Í' -H 'Range-Unit: |'"'"'' -H 'Prefer: -Infinity' http://0.0.0.0:43437/books_with_authors 6. Test Case ID: ab83rC - Response violates schema null is not of type "number" Validated against the response schema for status code 200. Schema at /definitions/books_with_authors/properties/price: { "type": "number", "format": "numeric" } Value: null [200] OK: `[{"id":22649,"title":"󸯃\u0013󪱫)","genre":"fiction","price":null,"author":"`\u0014\u0003Ì"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43437/books_with_authors __________________________________ GET /loans __________________________________ 1. Test Case ID: st0bCb - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 206 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Prefer: count=none' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/loans?id=&book_id=&borrower=&period=&returned=&select=&order=&offset=&limit=' 2. Test Case ID: 5Yq8Rj - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /loans` [200] OK: `[]` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/loans?select=' 3. Test Case ID: LflBQ3 - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/loans?id=&book_id=&borrower=&period=&returned=&select=&order=&offset=&limit=' 4. Test Case ID: lQXAqv - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Authorization` in header - violates `required` (was Authorization) [200] OK: `[]` Reproduce with: curl -X GET http://0.0.0.0:43437/loans 5. Test Case ID: CEEVNd - Server error - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json, application/vnd.pgrst.object+json;nulls=stripped, application/vnd.pgrst.object+json, text/csv - Undocumented HTTP status code Received: 500 Documented: 200, 206 [500] Internal Server Error: `Something went wrong` Reproduce with: curl -X GET -H 'Prefer: count=none' -H $'Range: Ð="\xc2\x8a5\xc2\x9f\xc2\xa0B¶' http://0.0.0.0:43437/loans ____________________________ GET /rpc/author_stats _____________________________ 1. Test Case ID: oixYQq - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"code":"PGRST202","details":"Searched for the function api.author_stats without parameters, but no matches were found in the schema cache.","hint":null,"message":"Could not find the function api.author_stats without parameters in the schema cache"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43437/rpc/author_stats 2. Test Case ID: IScjt8 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /rpc/author_stats` - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: Missing `Authorization` at header - Missing header not rejected Got 200 when missing required 'Authorization' header, expected 401 [200] OK: `{"books" : 1, "pages" : 387}` Reproduce with: curl -X GET 'http://0.0.0.0:43437/rpc/author_stats?author_id=%5BFiltered%5D' 3. Test Case ID: aoihvU - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"code":"22003","details":null,"hint":null,"message":"value \"9223372036854775808\" is out of range for type bigint"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/rpc/author_stats?author_id=%5BFiltered%5D' ______________________________ GET /rpc/lend_book ______________________________ 1. Test Case ID: u2RZwX - Unsupported methods Unsupported method GET returned 404, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [404] Not Found: `{"code":"PGRST202","details":"Searched for the function api.lend_book without parameters, but no matches were found in the schema cache.","hint":null,"message":"Could not find the function api.lend_book without parameters in the schema cache"}` Reproduce with: curl -X GET -H 'Prefer;' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"book_id": 0, "borrower": "", "days": 0}' http://0.0.0.0:43437/rpc/lend_book ____________________________ GET /rpc/search_books _____________________________ 1. Test Case ID: 7f7JYy - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /rpc/search_books` [200] OK: `[{"id":1,"author_id":1,"title":"The Dispossessed","isbn":"9780061054884","genre":"fiction","pages":387,"price":9.99,"published_at":null,"keywords":["anarchy","physics"],"details":{"series": "Hainish"},"in_print":true}, {"id":2,"author_id":2,"title":"Solaris","isbn":"9780156027601","genre":"science","pages":204,"price":12.50,"published_at":null,"keywords":["ocean"],"details":{},"in_print":true}]` Reproduce with: curl -X GET 'http://0.0.0.0:43437/rpc/search_books?query=' 2. Test Case ID: XcFtHO - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"code":"PGRST202","details":"Searched for the function api.search_books with parameter max_price, but no matches were found in the schema cache.","hint":"Perhaps you meant to call the function api.search_books(max_price, query)","message":"Could not find the function api.search_books(max_price) in the schema cache"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/rpc/search_books?max_price=0' 3. Test Case ID: WQFaEy - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: Missing `Authorization` at header - Missing header not rejected Got 200 when missing required 'Authorization' header, expected 401 [200] OK: `[]` Reproduce with: curl -X GET 'http://0.0.0.0:43437/rpc/search_books?query=&max_price=0' 4. Test Case ID: PTUbxd - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"code":"22P02","details":null,"hint":null,"message":"invalid input syntax for type numeric: \"null\""}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/rpc/search_books?query=&max_price=null&max_price=null' __________________________________ GET /tags ___________________________________ 1. Test Case ID: tkM81L - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 206 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Prefer: count=none' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/tags?id=&name=&select=&order=&offset=&limit=' 2. Test Case ID: hprCt9 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /tags` [200] OK: `[{"id":1,"name":"classic"}, {"id":2,"name":"sf"}, {"id":0,"name":""}]` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/tags?select=' 3. Test Case ID: ULDk1K - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X GET -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' 'http://0.0.0.0:43437/tags?id=&name=&select=&order=&offset=&limit=' 4. Test Case ID: RKtPoQ - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Authorization` in header - violates `required` (was Authorization) [200] OK: `[{"id":1,"name":"classic"}, {"id":2,"name":"sf"}, {"id":0,"name":"ç\u0016ï"}]` Reproduce with: curl -X GET http://0.0.0.0:43437/tags 5. Test Case ID: PaVwsX - Server error - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json, application/vnd.pgrst.object+json;nulls=stripped, application/vnd.pgrst.object+json, text/csv - Undocumented HTTP status code Received: 500 Documented: 200, 206 [500] Internal Server Error: `Something went wrong` Reproduce with: curl -X GET -H $'Range: %ú\xc2\xa0' -H 'Prefer: ]5I' -H 'Authorization: [Filtered]' -H 'Range-Unit: aS[JB' 'http://0.0.0.0:43437/tags?select=%F0%BA%9E%BDg' _______________________________ OPTIONS /authors _______________________________ 1. Test Case ID: jsF6SR - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: PUT List exactly the methods this resource supports in `Allow` [200] OK: Reproduce with: curl -X OPTIONS -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "name": "", "born": "2000-01-01", "country": "", "website": ""}' 'http://0.0.0.0:43437/authors?select=' ______________________________ OPTIONS /book_tags ______________________________ 1. Test Case ID: hhlaSR - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: PUT List exactly the methods this resource supports in `Allow` [200] OK: Reproduce with: curl -X OPTIONS -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"book_id": 0, "tag_id": 0}' 'http://0.0.0.0:43437/book_tags?select=' ________________________________ OPTIONS /books ________________________________ 1. Test Case ID: K8OdJf - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: PUT List exactly the methods this resource supports in `Allow` [200] OK: Reproduce with: curl -X OPTIONS -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "author_id": "[Filtered]", "title": "", "isbn": "", "genre": "fiction", "pages": 0, "price": 0, "published_at": "", "keywords": ["[Filtered]"], "details": null, "in_print": true}' 'http://0.0.0.0:43437/books?select=' ________________________________ OPTIONS /loans ________________________________ 1. Test Case ID: bgkKp5 - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: PUT List exactly the methods this resource supports in `Allow` [200] OK: Reproduce with: curl -X OPTIONS -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": "e3e70682-c209-1cac-a29f-6fbed82c07cd", "book_id": 0, "borrower": "", "period": "", "returned": false}' 'http://0.0.0.0:43437/loans?select=' ________________________________ OPTIONS /tags _________________________________ 1. Test Case ID: DfPlBB - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: PUT List exactly the methods this resource supports in `Allow` [200] OK: Reproduce with: curl -X OPTIONS -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "name": ""}' 'http://0.0.0.0:43437/tags?select=' ________________________________ PATCH /authors ________________________________ 1. Test Case ID: VUQiAO - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": -9223372036854775807, "name": "", "born": "2000-01-01", "country": "", "website": ""}' 'http://0.0.0.0:43437/authors?id=&name=&born=&country=&website=' 2. Test Case ID: swksNa - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X PATCH -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"id": -9223372036854775807, "name": "", "born": "2000-01-01", "country": "", "website": ""}' 'http://0.0.0.0:43437/authors?id=&name=&born=&country=&website=' 3. Test Case ID: kkk5Tj - Undocumented HTTP status code Received: 409 Documented: 204 [409] Conflict: `{"code":"23505","details":"Key (id)=(-2533304) already exists.","hint":null,"message":"duplicate key value violates unique constraint \"authors_pkey\""}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": -2533304, "name": "\u00cb", "born": "1929-10-21"}' http://0.0.0.0:43437/authors 4. Test Case ID: rNXb4b - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `type` (was object, became boolean) [204] No Content: Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Prefer: return=none' -H 'Content-Type: application/json' -d true http://0.0.0.0:43437/authors 5. Test Case ID: apGfsU - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `required` (was id, name) [200] OK: `[]` Reproduce with: curl -X PATCH -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{}' http://0.0.0.0:43437/authors _______________________________ PATCH /book_tags _______________________________ 1. Test Case ID: uPmprJ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"book_id": 0, "tag_id": 0}' 'http://0.0.0.0:43437/book_tags?book_id=&tag_id=' 2. Test Case ID: dRRKnE - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X PATCH -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"book_id": 0, "tag_id": 0}' 'http://0.0.0.0:43437/book_tags?book_id=&tag_id=' 3. Test Case ID: ORQFgK - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [204] No Content: Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"book_id": 22649, "tag_id": 0}' http://0.0.0.0:43437/book_tags 4. Test Case ID: kRwYxn - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: - header: violates `required` (was Authorization) - body: violates `minimum` at /properties/book_id (was 0, became -9223372036854775809) [204] No Content: Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"book_id": -9223372036854775809, "tag_id": 1}' http://0.0.0.0:43437/book_tags _________________________________ PATCH /books _________________________________ 1. Test Case ID: K9Qunl - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "author_id": "[Filtered]", "title": "", "isbn": "", "genre": "fiction", "pages": 0, "price": 0, "published_at": "", "keywords": ["[Filtered]"], "details": {}, "in_print": true}' 'http://0.0.0.0:43437/books?id=&author_id=%5BFiltered%5D&title=&isbn=&genre=&pages=&price=&published_at=&keywords=%5BFiltered%5D&details=&in_print=' 2. Test Case ID: tXR6nj - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X PATCH -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"id": 0, "author_id": "[Filtered]", "title": "", "isbn": "", "genre": "fiction", "pages": 0, "price": 0, "published_at": "", "keywords": ["[Filtered]"], "details": {}, "in_print": true}' 'http://0.0.0.0:43437/books?id=&author_id=%5BFiltered%5D&title=&isbn=&genre=&pages=&price=&published_at=&keywords=%5BFiltered%5D&details=&in_print=' 3. Test Case ID: Qh78BL - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [204] No Content: Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"author_id": "[Filtered]", "details": [0.0], "genre": "science", "id": 22649, "in_print": false, "keywords": ["[Filtered]"], "title": ""}' http://0.0.0.0:43437/books 4. Test Case ID: zH90hp - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `Prefer` in header - violates `enum` at /properties/Prefer [204] No Content: Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Prefer;' -H 'Content-Type: application/json' -d '{"author_id": "[Filtered]", "details": 0.0, "genre": "poetry", "id": 22649, "in_print": false, "keywords": ["[Filtered]"], "title": ""}' http://0.0.0.0:43437/books 5. Test Case ID: yfB2qe - Undocumented HTTP status code Received: 200 Documented: 204 [200] OK: `[]` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"author_id": "[Filtered]", "details": 0.0, "genre": "poetry", "id": 1, "in_print": false, "keywords": ["[Filtered]"], "title": ""}' http://0.0.0.0:43437/books _________________________________ PATCH /loans _________________________________ 1. Test Case ID: atMhIa - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": "e3e70682-c209-1cac-a29f-6fbed82c07cd", "book_id": 0, "borrower": "", "period": "", "returned": false}' 'http://0.0.0.0:43437/loans?id=&book_id=&borrower=&period=&returned=' 2. Test Case ID: XZpAJM - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X PATCH -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"id": "e3e70682-c209-1cac-a29f-6fbed82c07cd", "book_id": 0, "borrower": "", "period": "", "returned": false}' 'http://0.0.0.0:43437/loans?id=&book_id=&borrower=&period=&returned=' 3. Test Case ID: Lsxqd7 - Undocumented HTTP status code Received: 401 Documented: 204 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table loans"}` Reproduce with: curl -X PATCH -H 'Content-Type: application/json' -d '{"borrower": "", "book_id": 22649, "id": "29278750-733a-5188-8c46-bbc5ef230f42", "returned": true, "period": "\u00ef\u0099"}' http://0.0.0.0:43437/loans 4. Test Case ID: PQxR63 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: - header: violates `required` (was Authorization) - body: violates `format:uuid` at /properties/id (was "e3e70682-c209-3cac-a29f-6fbed82c07cd", became "g3e70682-c209-3cac-a29f-6fbed82c07cd") - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [204] No Content: Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"book_id": 0, "borrower": "", "id": "g3e70682-c209-3cac-a29f-6fbed82c07cd", "period": "", "returned": true}' http://0.0.0.0:43437/loans _________________________________ PATCH /tags __________________________________ 1. Test Case ID: zmxxyp - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "name": ""}' 'http://0.0.0.0:43437/tags?id=&name=' 2. Test Case ID: H8pTVW - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting \"not\" or operator (eq, gt, ...)","hint":null,"message":"\"failed to parse filter ()\" (line 1, column 1)"}` Reproduce with: curl -X PATCH -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"id": 0, "name": ""}' 'http://0.0.0.0:43437/tags?id=&name=' 3. Test Case ID: 3gSIR2 - Undocumented HTTP status code Received: 409 Documented: 204 [409] Conflict: `{"code":"23505","details":"Key (id)=(0) already exists.","hint":null,"message":"duplicate key value violates unique constraint \"tags_pkey\""}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "name": ""}' http://0.0.0.0:43437/tags 4. Test Case ID: HJZCJB - Undocumented HTTP status code Received: 401 Documented: 204 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table tags"}` Reproduce with: curl -X PATCH -H 'Content-Type: application/json' -d '{"id": 0, "name": ""}' http://0.0.0.0:43437/tags ________________________________ POST /authors _________________________________ 1. Test Case ID: VTDVky - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 201 [400] Bad Request: `{"code":"23514","details":"Failing row contains (0, , 2000-01-01, , ).","hint":null,"message":"new row for relation \"authors\" violates check constraint \"authors_name_check\""}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "name": "", "born": "2000-01-01", "country": "", "website": ""}' 'http://0.0.0.0:43437/authors?select=' 2. Test Case ID: Asdpbq - Undocumented HTTP status code Received: 401 Documented: 201 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table authors"}` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"id": 0, "name": "", "born": "2000-01-01", "country": "", "website": ""}' 'http://0.0.0.0:43437/authors?select=' 3. Test Case ID: tbi6AB - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - incorrect type [201] Created: `[]` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '"AAA"' 'http://0.0.0.0:43437/authors?select=' 4. Test Case ID: gKw7pP - Undocumented HTTP status code Received: 409 Documented: 201 [409] Conflict: `{"code":"23505","details":"Key (id)=(0) already exists.","hint":null,"message":"duplicate key value violates unique constraint \"authors_pkey\""}` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "name": [null, null], "born": "2000-01-01", "country": "", "website": ""}' 'http://0.0.0.0:43437/authors?select=' 5. Test Case ID: HN2bIa - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [201] Created: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"country": "!\u0019", "id": -202297, "name": "=", "born": "0116-01-16"}' http://0.0.0.0:43437/authors _______________________________ POST /book_tags ________________________________ 1. Test Case ID: jboeJA - Undocumented HTTP status code Received: 409 Documented: 201 [409] Conflict: `{"code":"23503","details":"Key (book_id)=(0) is not present in table \"books\".","hint":null,"message":"insert or update on table \"book_tags\" violates foreign key constraint \"book_tags_book_id_fkey\""}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"book_id": 0, "tag_id": 0}' 'http://0.0.0.0:43437/book_tags?select=' 2. Test Case ID: 7eiNww - Undocumented HTTP status code Received: 401 Documented: 201 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table book_tags"}` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"book_id": 0, "tag_id": 0}' 'http://0.0.0.0:43437/book_tags?select=' 3. Test Case ID: 9vwZWd - Undocumented HTTP status code Received: 400 Documented: 201 [400] Bad Request: `{"code":"PGRST102","details":null,"hint":null,"message":"parse error (not enough input) at \"\""}` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: text/csv' -d '[null, null]' 'http://0.0.0.0:43437/book_tags?select=' 4. Test Case ID: YrKHab - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"code":"PGRST102","details":null,"hint":null,"message":"parse error (Failed reading: satisfy) at \"\\\"book_id\\\": 0, \\\"tag_id\\\": 2147483646}\""}` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: text/csv' -d '{"book_id": 0, "tag_id": 2147483646}' 'http://0.0.0.0:43437/book_tags?select=' 5. Test Case ID: scjybT - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - incorrect type [201] Created: `[]` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '"AAA"' 'http://0.0.0.0:43437/book_tags?select=' _________________________________ POST /books __________________________________ 1. Test Case ID: W0wqNI - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 201 [400] Bad Request: `{"code":"23514","details":null,"hint":null,"message":"value for domain isbn violates check constraint \"isbn_check\""}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "author_id": "[Filtered]", "title": "", "isbn": "", "genre": "fiction", "pages": 0, "price": 0, "published_at": "", "keywords": ["[Filtered]"], "details": null, "in_print": true}' 'http://0.0.0.0:43437/books?select=' 2. Test Case ID: nMtElL - Undocumented HTTP status code Received: 401 Documented: 201 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table books"}` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"id": 0, "author_id": "[Filtered]", "title": "", "isbn": "", "genre": "fiction", "pages": 0, "price": 0, "published_at": "", "keywords": ["[Filtered]"], "details": null, "in_print": true}' 'http://0.0.0.0:43437/books?select=' 3. Test Case ID: CgAX1X - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - incorrect type [201] Created: `[]` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '"AAA"' 'http://0.0.0.0:43437/books?select=' 4. Test Case ID: VSXRZS - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [201] Created: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"author_id": "[Filtered]", "details": [{"\ud98c\udf1c": {"": -3.751518126398131e+16, "fq\uda88\uddcf\udab5\udc37\u0099\u0091\u00be": false}, "\u00a2\u009e\u00be\u00f4\u00ea\ud8b3\ude48": [null, 11434469368547, null]}, {}, -28231, {}, null, {"\ud83d\ude48\u009a'"'"'\u000b\u0004": "\u00f9&\u0087", "\ud96b\udd83\udb47\udc5f\u00cd\ud84f\ude4dK\u00cd\ud8ec\udd67\u0091\u00d2M\uda7d\udd61\u00ddK_w": -179, "&\ud8d6\ude72": -7200844674147945.0}, [true, {}, []], null, [[], {"\u001b~B\u00a8": null}, [-5241, null, false]]], "genre": "science", "id": 22649, "in_print": true, "keywords": ["[Filtered]"], "title": ""}' http://0.0.0.0:43437/books 5. Test Case ID: 6Kuw80 - Undocumented HTTP status code Received: 409 Documented: 201 [409] Conflict: `{"code":"23505","details":"Key (id)=(0) already exists.","hint":null,"message":"duplicate key value violates unique constraint \"books_pkey\""}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Prefer: return=none' -H 'Content-Type: application/json' -d '{"author_id": "[Filtered]", "keywords": ["[Filtered]"], "genre": "science", "id": 0, "in_print": false, "details": [0.0], "title": ""}' http://0.0.0.0:43437/books 6. Test Case ID: ZRKZeB - Undocumented HTTP status code Received: 200 Documented: 201 [200] OK: Reproduce with: curl -X POST -H 'Prefer: resolution=merge-duplicates' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"author_id": "[Filtered]", "details": false, "id": 5, "genre": "science", "in_print": false, "keywords": ["[Filtered]"], "title": ""}' http://0.0.0.0:43437/books _________________________________ POST /loans __________________________________ 1. Test Case ID: rX150q - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 201 [400] Bad Request: `{"code":"22P02","details":"Missing left parenthesis or bracket.","hint":null,"message":"malformed range literal: \"\""}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": "e3e70682-c209-1cac-a29f-6fbed82c07cd", "book_id": 0, "borrower": "", "period": "", "returned": false}' 'http://0.0.0.0:43437/loans?select=' 2. Test Case ID: cDkleM - Undocumented HTTP status code Received: 401 Documented: 201 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table loans"}` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"id": "e3e70682-c209-1cac-a29f-6fbed82c07cd", "book_id": 0, "borrower": "", "period": "", "returned": false}' 'http://0.0.0.0:43437/loans?select=' 3. Test Case ID: sRUTI2 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - incorrect type [201] Created: `[]` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '"AAA"' 'http://0.0.0.0:43437/loans?select=' ____________________________ POST /rpc/author_stats ____________________________ 1. Test Case ID: AkHYJ5 - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `POST /rpc/author_stats` [200] OK: `{"books" : 0, "pages" : 0}` Reproduce with: curl -X POST -H 'Content-Type: application/json' -d '{"author_id": "[Filtered]"}' http://0.0.0.0:43437/rpc/author_stats 2. Test Case ID: KcQUhD - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"code":"PGRST202","details":"Searched for the function api.author_stats without parameters or with a single unnamed json/jsonb parameter, but no matches were found in the schema cache.","hint":null,"message":"Could not find the function api.author_stats without parameters in the schema cache"}` Reproduce with: curl -X POST -H 'Prefer;' -H 'Authorization: [Filtered]' http://0.0.0.0:43437/rpc/author_stats 3. Test Case ID: NP07wn - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: Missing `Authorization` at header - Missing header not rejected Got 200 when missing required 'Authorization' header, expected 401 [200] OK: `{"books" : 0, "pages" : 0}` Reproduce with: curl -X POST -H 'Prefer;' -H 'Content-Type: application/json' -d '{"author_id": "[Filtered]"}' http://0.0.0.0:43437/rpc/author_stats 4. Test Case ID: YPums0 - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"code":"PGRST102","details":null,"hint":null,"message":"parse error (not enough input) at \"\""}` Reproduce with: curl -X POST -H 'Prefer;' -H 'Authorization: [Filtered]' -H 'Content-Type: text/csv' -d '[null, null]' http://0.0.0.0:43437/rpc/author_stats 5. Test Case ID: tC6g7s - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"code":"PGRST102","details":null,"hint":null,"message":"parse error (Failed reading: satisfy) at \"\\\"author_id\\\": 9223372036854775806}\""}` Reproduce with: curl -X POST -H 'Prefer;' -H 'Authorization: [Filtered]' -H 'Content-Type: text/csv' -d '{"author_id": 9223372036854775806}' http://0.0.0.0:43437/rpc/author_stats _____________________________ POST /rpc/lend_book ______________________________ 1. Test Case ID: 5gacbb - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"code":"22023","details":null,"hint":null,"message":"days must be between 1 and 90"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"book_id": 0, "borrower": "", "days": 0}' http://0.0.0.0:43437/rpc/lend_book 2. Test Case ID: Zg2wTz - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"code":"PGRST202","details":"Searched for the function api.lend_book without parameters or with a single unnamed json/jsonb parameter, but no matches were found in the schema cache.","hint":null,"message":"Could not find the function api.lend_book without parameters in the schema cache"}` Reproduce with: curl -X POST -H 'Prefer;' -H 'Authorization: [Filtered]' http://0.0.0.0:43437/rpc/lend_book 3. Test Case ID: Eh9n9q - Missing header not rejected Got 400 when missing required 'Authorization' header, expected 401 [400] Bad Request: `{"code":"22023","details":null,"hint":null,"message":"days must be between 1 and 90"}` Reproduce with: curl -X POST -H 'Prefer;' -H 'Content-Type: application/json' -d '{"book_id": 0, "borrower": "", "days": 0}' http://0.0.0.0:43437/rpc/lend_book 4. Test Case ID: 44mGda - Undocumented HTTP status code Received: 409 Documented: 200 [409] Conflict: `{"code":"23503","details":"Key (book_id)=(0) is not present in table \"books\".","hint":null,"message":"insert or update on table \"loans\" violates foreign key constraint \"loans_book_id_fkey\""}` Reproduce with: curl -X POST -H 'Prefer;' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"book_id": 0, "borrower": "", "days": null}' http://0.0.0.0:43437/rpc/lend_book 5. Test Case ID: EFY4Tx - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table loans"}` Reproduce with: curl -X POST -H 'Content-Type: application/json' -d '{"book_id": -2293765, "borrower": ""}' http://0.0.0.0:43437/rpc/lend_book ____________________________ POST /rpc/search_books ____________________________ 1. Test Case ID: iKJEDm - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `POST /rpc/search_books` [200] OK: `[]` Reproduce with: curl -X POST -H 'Content-Type: application/json' -d '{"max_price": 0, "query": ""}' http://0.0.0.0:43437/rpc/search_books 2. Test Case ID: eUcCSk - Undocumented HTTP status code Received: 404 Documented: 200 [404] Not Found: `{"code":"PGRST202","details":"Searched for the function api.search_books without parameters or with a single unnamed json/jsonb parameter, but no matches were found in the schema cache.","hint":null,"message":"Could not find the function api.search_books without parameters in the schema cache"}` Reproduce with: curl -X POST -H 'Prefer;' -H 'Authorization: [Filtered]' http://0.0.0.0:43437/rpc/search_books 3. Test Case ID: zglUB7 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: Missing `Authorization` at header - Missing header not rejected Got 200 when missing required 'Authorization' header, expected 401 [200] OK: `[]` Reproduce with: curl -X POST -H 'Prefer;' -H 'Content-Type: application/json' -d '{"max_price": 0, "query": ""}' http://0.0.0.0:43437/rpc/search_books 4. Test Case ID: yrNHgp - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"code":"PGRST102","details":null,"hint":null,"message":"parse error (not enough input) at \"\""}` Reproduce with: curl -X POST -H 'Prefer;' -H 'Authorization: [Filtered]' -H 'Content-Type: text/csv' -d '[null, null]' http://0.0.0.0:43437/rpc/search_books 5. Test Case ID: nK24Q8 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"code":"PGRST102","details":null,"hint":null,"message":"parse error (Failed reading: satisfy) at \"\\\"query\\\": \\\"\\\"}\""}` Reproduce with: curl -X POST -H 'Prefer;' -H 'Authorization: [Filtered]' -H 'Content-Type: text/csv' -d '{"query": ""}' http://0.0.0.0:43437/rpc/search_books __________________________________ POST /tags __________________________________ 1. Test Case ID: 3zfnEk - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [201] Created: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "name": ""}' 'http://0.0.0.0:43437/tags?select=' 2. Test Case ID: cVzaQF - Undocumented HTTP status code Received: 401 Documented: 201 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table tags"}` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"id": 0, "name": ""}' 'http://0.0.0.0:43437/tags?select=' 3. Test Case ID: BtKuJd - Undocumented HTTP status code Received: 409 Documented: 201 [409] Conflict: `{"code":"23505","details":"Key (id)=(0) already exists.","hint":null,"message":"duplicate key value violates unique constraint \"tags_pkey\""}` Reproduce with: curl -X POST -H 'Prefer: {}' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "name": ""}' 'http://0.0.0.0:43437/tags?select=' 4. Test Case ID: VrtCqN - Undocumented HTTP status code Received: 200 Documented: 201 [200] OK: Reproduce with: curl -X POST -H 'Prefer: resolution=merge-duplicates' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "name": ""}' 'http://0.0.0.0:43437/tags?select=' 5. Test Case ID: Vq5Atd - Undocumented HTTP status code Received: 400 Documented: 201 [400] Bad Request: `{"code":"PGRST102","details":null,"hint":null,"message":"parse error (not enough input) at \"\""}` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: text/csv' -d '[null, null]' 'http://0.0.0.0:43437/tags?select=' 6. Test Case ID: odUwBA - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"code":"PGRST102","details":null,"hint":null,"message":"parse error (Failed reading: satisfy) at \"\\\"id\\\": 0, \\\"name\\\": \\\"0000000000000000000000000000000000000000000000000\\\"}\""}` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: text/csv' -d '{"id": 0, "name": "0000000000000000000000000000000000000000000000000"}' 'http://0.0.0.0:43437/tags?select=' 7. Test Case ID: vh6cOd - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - incorrect type [201] Created: `[]` Reproduce with: curl -X POST -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '"AAA"' 'http://0.0.0.0:43437/tags?select=' _________________________________ PUT /authors _________________________________ 1. Test Case ID: EgV9sL - Unsupported methods PUT returned 405 without required `Allow` header Add `Allow` header listing supported methods (required by RFC 9110) [405] Method Not Allowed: `{"code":"PGRST105","details":null,"hint":null,"message":"Filters must include all and only primary key columns with 'eq' operators"}` Reproduce with: curl -X PUT -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "name": "", "born": "2000-01-01", "country": "", "website": ""}' 'http://0.0.0.0:43437/authors?select=' ________________________________ PUT /book_tags ________________________________ 1. Test Case ID: Cfl82P - Unsupported methods PUT returned 405 without required `Allow` header Add `Allow` header listing supported methods (required by RFC 9110) [405] Method Not Allowed: `{"code":"PGRST105","details":null,"hint":null,"message":"Filters must include all and only primary key columns with 'eq' operators"}` Reproduce with: curl -X PUT -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"book_id": 0, "tag_id": 0}' 'http://0.0.0.0:43437/book_tags?select=' __________________________________ PUT /books __________________________________ 1. Test Case ID: NdHMWU - Unsupported methods PUT returned 405 without required `Allow` header Add `Allow` header listing supported methods (required by RFC 9110) [405] Method Not Allowed: `{"code":"PGRST105","details":null,"hint":null,"message":"Filters must include all and only primary key columns with 'eq' operators"}` Reproduce with: curl -X PUT -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "author_id": "[Filtered]", "title": "", "isbn": "", "genre": "fiction", "pages": 0, "price": 0, "published_at": "", "keywords": ["[Filtered]"], "details": null, "in_print": true}' 'http://0.0.0.0:43437/books?select=' ___________________________ PUT /books_with_authors ____________________________ 1. Test Case ID: jUNzCj - Unsupported methods Unsupported method PUT returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `{"code":"PGRST100","details":"unexpected end of input expecting field name (* or [a..z0..9_$])","hint":null,"message":"\"failed to parse order ()\" (line 1, column 1)"}` Reproduce with: curl -X PUT -H 'Range;' -H 'Range-Unit: items' -H 'Prefer: count=none' -H 'Authorization: [Filtered]' 'http://0.0.0.0:43437/books_with_authors?id=&title=&genre=&price=&author=%5BFiltered%5D&select=&order=&offset=&limit=' __________________________________ PUT /loans __________________________________ 1. Test Case ID: dyzFol - Unsupported methods PUT returned 405 without required `Allow` header Add `Allow` header listing supported methods (required by RFC 9110) [405] Method Not Allowed: `{"code":"PGRST105","details":null,"hint":null,"message":"Filters must include all and only primary key columns with 'eq' operators"}` Reproduce with: curl -X PUT -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": "e3e70682-c209-1cac-a29f-6fbed82c07cd", "book_id": 0, "borrower": "", "period": "", "returned": false}' 'http://0.0.0.0:43437/loans?select=' ____________________________ PUT /rpc/author_stats _____________________________ 1. Test Case ID: uW9X6c - Unsupported methods PUT returned 405 without required `Allow` header Add `Allow` header listing supported methods (required by RFC 9110) [405] Method Not Allowed: `{"code":"PGRST101","details":null,"hint":null,"message":"Cannot use the PUT method on RPC"}` Reproduce with: curl -X PUT -H 'Prefer;' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"author_id": "[Filtered]"}' http://0.0.0.0:43437/rpc/author_stats ______________________________ PUT /rpc/lend_book ______________________________ 1. Test Case ID: RIl4li - Unsupported methods PUT returned 405 without required `Allow` header Add `Allow` header listing supported methods (required by RFC 9110) [405] Method Not Allowed: `{"code":"PGRST101","details":null,"hint":null,"message":"Cannot use the PUT method on RPC"}` Reproduce with: curl -X PUT -H 'Prefer;' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"book_id": 0, "borrower": "", "days": 0}' http://0.0.0.0:43437/rpc/lend_book ____________________________ PUT /rpc/search_books _____________________________ 1. Test Case ID: U43npw - Unsupported methods PUT returned 405 without required `Allow` header Add `Allow` header listing supported methods (required by RFC 9110) [405] Method Not Allowed: `{"code":"PGRST101","details":null,"hint":null,"message":"Cannot use the PUT method on RPC"}` Reproduce with: curl -X PUT -H 'Prefer;' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"max_price": 0, "query": ""}' http://0.0.0.0:43437/rpc/search_books __________________________________ PUT /tags ___________________________________ 1. Test Case ID: wa04RZ - Unsupported methods PUT returned 405 without required `Allow` header Add `Allow` header listing supported methods (required by RFC 9110) [405] Method Not Allowed: `{"code":"PGRST105","details":null,"hint":null,"message":"Filters must include all and only primary key columns with 'eq' operators"}` Reproduce with: curl -X PUT -H 'Prefer: return=representation' -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 0, "name": ""}' 'http://0.0.0.0:43437/tags?select=' ________________________________ Stateful tests ________________________________ 1. Test Case ID: 01pvdd - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [204] No Content: Reproduce with: curl -X GET http://0.0.0.0:43437/authors curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 125388, "country": "\u0081I", "name": "\u001e\u00c3\u00a7\u00d6\u00aa\u00e6\u0010\u00b3\ud872\udc93\u00a0\udb22\udc8e-\u001d\u0013\u001eQ\udb46\udd00", "born": "2000-01-01"}' http://0.0.0.0:43437/authors 2. Test Case ID: KozuZ1 - Undocumented HTTP status code Received: 401 Documented: 204 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table authors"}` Reproduce with: curl -X GET http://0.0.0.0:43437/authors curl -X PATCH -H 'Content-Type: application/json' -d '{"id": 0, "name": ""}' http://0.0.0.0:43437/authors 3. Test Case ID: j8GqBe - Response violates schema (2 violations) null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/authors/properties/born: { "type": "string", "format": "date" } Value: null null is not of type "string" Validated against the response schema for status code 200. Schema at /definitions/authors/properties/country: { "type": "string", "format": "character", "maxLength": 2 } Value: null [200] OK: `[{"id":-161332,"name":"responses","born":null,"country":null,"website":null}]` Reproduce with: curl -X GET http://0.0.0.0:43437/authors 4. Test Case ID: BsIRKv - Undocumented HTTP status code Received: 401 Documented: 204 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table book_tags"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43437/tags curl -X PATCH -H 'Content-Type: application/json' -d '{"book_id": 22649, "tag_id": 0}' http://0.0.0.0:43437/book_tags 5. Test Case ID: RBAIXS - Undocumented HTTP status code Received: 401 Documented: 204 [401] Unauthorized: `{"code":"42501","details":null,"hint":null,"message":"permission denied for table books"}` Reproduce with: curl -X GET http://0.0.0.0:43437/books curl -X PATCH -H 'Content-Type: application/json' -d '{"author_id": "[Filtered]", "details": [0.0], "genre": "science", "id": 22649, "in_print": false, "keywords": ["[Filtered]"], "title": ""}' http://0.0.0.0:43437/books 6. Test Case ID: V6jseA - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [201] Created: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:43437/loans 7. Test Case ID: OaMVO2 - Undocumented HTTP status code Received: 200 Documented: 201 [200] OK: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Prefer: resolution=merge-duplicates' -H 'Content-Type: application/json' -d '{"id": 3320278, "name": "o,o\udab5\udf75\u00a3I\u00d9\udae9\ude1d"}' http://0.0.0.0:43437/authors 8. Test Case ID: ZZAElK - Undocumented HTTP status code Received: 200 Documented: 204 [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Range: bytes=507-1388' -H 'Prefer: count=none' -H 'Range-Unit: started_at' http://0.0.0.0:43437/tags curl -X PATCH -H 'Authorization: [Filtered]' -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"id": 3, "name": "\udbca\udfe1\u0002\u000b"}' http://0.0.0.0:43437/tags 9. Test Case ID: 4GAD7B - Missing Content-Type header The following media types are documented in the schema: - `application/json` - `application/vnd.pgrst.object+json;nulls=stripped` - `application/vnd.pgrst.object+json` - `text/csv` [204] No Content: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Range-Unit: /$ un!Wj Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"id": 11699081, "name": "{\ud9d1\udea8"}' 'http://0.0.0.0:43437/tags?select=' curl -X PATCH -H 'Authorization: [Filtered]' -H 'Prefer: return=minimal' -H 'Content-Type: application/json' -d '{"id": 11699081}' http://0.0.0.0:43437/tags 13. Test Case ID: yULcqT - Server error - Undocumented Content-Type Received: text/plain; charset=utf-8 Documented: application/json, application/vnd.pgrst.object+json;nulls=stripped, application/vnd.pgrst.object+json, text/csv - Undocumented HTTP status code Received: 500 Documented: 200, 206 [500] Internal Server Error: `Something went wrong` Reproduce with: curl -X GET -H 'Range: Uá' -H 'Authorization: [Filtered]' -H 'Prefer: Zg#' http://0.0.0.0:43437/books 14. Test Case ID: b1GY1K - Undocumented HTTP status code Received: 200 Documented: 204 [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:43437/authors curl -X PATCH -H 'Authorization: [Filtered]' -H 'Prefer: return=representation' -H 'Content-Type: application/json' -d '{"id": -1048576, "name": ""}' http://0.0.0.0:43437/authors =================================== SUMMARY ==================================== API Operations: Selected: 26/26 Tested: 26 Test Phases: ⏭ Examples ❌ Coverage ❌ Fuzzing ❌ Stateful Failures: ❌ API accepts requests without authentication: 10 ❌ Server error: 6 ❌ Response violates schema: 8 ❌ API accepted schema-violating request: 26 ❌ API rejected schema-compliant request: 24 ❌ Invalid Allow header: 5 ❌ Missing Content-Type header: 14 ❌ Missing header not rejected: 21 ❌ Undocumented Content-Type: 6 ❌ Undocumented HTTP status code: 72 ❌ Unsupported methods: 10 Test cases: 528821 generated, 161 found 202 unique failures, 327 errored, 29241 skipped Seed: 322363504308708779087548792568531345857 =========================== 202 failures in 3600.02s ===========================