Test Oracle Generation for REST APIs
The number and complexity of test case generation tools for REST APIs have significantly increased in recent years. These tools excel in automating input generation but are limited by their test oracles, which can only detect crashes, regressions, and violations of API specifications or design best...
| Autores: | , , , |
|---|---|
| Tipo de recurso: | artículo |
| Estado: | Versión publicada |
| Fecha de publicación: | 2025 |
| País: | España |
| Institución: | Universidad de Sevilla (US) |
| Repositorio: | idUS. Depósito de Investigación de la Universidad de Sevilla |
| OAI Identifier: | oai:dnet:idus________::a9f9770f189f31f9f0f085fdf1a28df2 |
| Acceso en línea: | https://hdl.handle.net/11441/186407 https://doi.org/10.1145/3726524 |
| Access Level: | acceso abierto |
| Palabra clave: | REST APIs test oracle invariant detection automated testing |
| id |
ES_9ec24c8cd2c8b3724513f5279389cab4 |
|---|---|
| oai_identifier_str |
oai:dnet:idus________::a9f9770f189f31f9f0f085fdf1a28df2 |
| network_acronym_str |
ES |
| network_name_str |
España |
| repository_id_str |
|
| spelling |
Test Oracle Generation for REST APIsAlonso Valenzuela, Juan CarlosErnst, Michael D.Segura Rueda, SergioRuiz Cortés, AntonioREST APIstest oracleinvariant detectionautomated testingThe number and complexity of test case generation tools for REST APIs have significantly increased in recent years. These tools excel in automating input generation but are limited by their test oracles, which can only detect crashes, regressions, and violations of API specifications or design best practices. This article introduces AGORA+, an approach for generating test oracles for REST APIs through the detection of invariants—output properties that should always hold. AGORA+ learns the expected behavior of an API by analyzing API requests and their corresponding responses. We enhanced the Daikon tool for dynamic detection of likely invariants, adding new invariant types and creating a front-end called Beet. Beet translates any OpenAPI specification and a set of API requests and responses into Daikon inputs. AGORA+ can detect 106 different types of invariants in REST APIs. We also developed PostmanAssertify, which converts the invariants identified by AGORA+ into executable JavaScript assertions. AGORA+ achieved a precision of 80% on 25 operations from 20 industrial APIs. It also identified 48% of errors systematically seeded in the outputs of the APIs under test. AGORA+ uncovered 32 bugs in popular APIs, including Amadeus, Deutschebahn, GitHub, Marvel, NYTimesBooks, and YouTube, leading to fixes and documentation updates.Association for Computing Machinery (ACM)Lenguajes y Sistemas InformáticosTIC205: Ingeniería del Software AplicadaMinisterio de Ciencia e Innovación (MICIN). EspañaEuropean Union (UE)2025info:eu-repo/semantics/articleinfo:eu-repo/semantics/publishedVersionapplication/pdfapplication/pdfhttps://hdl.handle.net/11441/186407https://doi.org/10.1145/3726524reponame:idUS. Depósito de Investigación de la Universidad de Sevillainstname:Universidad de Sevilla (US)InglésACM Transactions on Software Engineering and Methodology, 35, 1 p.-37 p.. PID2021-126227NB-C22PID2021-126227NB-C21TED2021-131023B-C21https://dl.acm.org/doi/10.1145/3726524info:eu-repo/semantics/openAccessoai:dnet:idus________::a9f9770f189f31f9f0f085fdf1a28df22026-06-17T12:51:07Z |
| dc.title.none.fl_str_mv |
Test Oracle Generation for REST APIs |
| title |
Test Oracle Generation for REST APIs |
| spellingShingle |
Test Oracle Generation for REST APIs Alonso Valenzuela, Juan Carlos REST APIs test oracle invariant detection automated testing |
| title_short |
Test Oracle Generation for REST APIs |
| title_full |
Test Oracle Generation for REST APIs |
| title_fullStr |
Test Oracle Generation for REST APIs |
| title_full_unstemmed |
Test Oracle Generation for REST APIs |
| title_sort |
Test Oracle Generation for REST APIs |
| dc.creator.none.fl_str_mv |
Alonso Valenzuela, Juan Carlos Ernst, Michael D. Segura Rueda, Sergio Ruiz Cortés, Antonio |
| author |
Alonso Valenzuela, Juan Carlos |
| author_facet |
Alonso Valenzuela, Juan Carlos Ernst, Michael D. Segura Rueda, Sergio Ruiz Cortés, Antonio |
| author_role |
author |
| author2 |
Ernst, Michael D. Segura Rueda, Sergio Ruiz Cortés, Antonio |
| author2_role |
author author author |
| dc.contributor.none.fl_str_mv |
Lenguajes y Sistemas Informáticos TIC205: Ingeniería del Software Aplicada Ministerio de Ciencia e Innovación (MICIN). España European Union (UE) |
| dc.subject.none.fl_str_mv |
REST APIs test oracle invariant detection automated testing |
| topic |
REST APIs test oracle invariant detection automated testing |
| description |
The number and complexity of test case generation tools for REST APIs have significantly increased in recent years. These tools excel in automating input generation but are limited by their test oracles, which can only detect crashes, regressions, and violations of API specifications or design best practices. This article introduces AGORA+, an approach for generating test oracles for REST APIs through the detection of invariants—output properties that should always hold. AGORA+ learns the expected behavior of an API by analyzing API requests and their corresponding responses. We enhanced the Daikon tool for dynamic detection of likely invariants, adding new invariant types and creating a front-end called Beet. Beet translates any OpenAPI specification and a set of API requests and responses into Daikon inputs. AGORA+ can detect 106 different types of invariants in REST APIs. We also developed PostmanAssertify, which converts the invariants identified by AGORA+ into executable JavaScript assertions. AGORA+ achieved a precision of 80% on 25 operations from 20 industrial APIs. It also identified 48% of errors systematically seeded in the outputs of the APIs under test. AGORA+ uncovered 32 bugs in popular APIs, including Amadeus, Deutschebahn, GitHub, Marvel, NYTimesBooks, and YouTube, leading to fixes and documentation updates. |
| publishDate |
2025 |
| dc.date.none.fl_str_mv |
2025 |
| dc.type.none.fl_str_mv |
info:eu-repo/semantics/article info:eu-repo/semantics/publishedVersion |
| format |
article |
| status_str |
publishedVersion |
| dc.identifier.none.fl_str_mv |
https://hdl.handle.net/11441/186407 https://doi.org/10.1145/3726524 |
| url |
https://hdl.handle.net/11441/186407 https://doi.org/10.1145/3726524 |
| dc.language.none.fl_str_mv |
Inglés |
| language_invalid_str_mv |
Inglés |
| dc.relation.none.fl_str_mv |
ACM Transactions on Software Engineering and Methodology, 35, 1 p.-37 p.. PID2021-126227NB-C22 PID2021-126227NB-C21 TED2021-131023B-C21 https://dl.acm.org/doi/10.1145/3726524 |
| dc.rights.none.fl_str_mv |
info:eu-repo/semantics/openAccess |
| eu_rights_str_mv |
openAccess |
| dc.format.none.fl_str_mv |
application/pdf application/pdf |
| dc.publisher.none.fl_str_mv |
Association for Computing Machinery (ACM) |
| publisher.none.fl_str_mv |
Association for Computing Machinery (ACM) |
| dc.source.none.fl_str_mv |
reponame:idUS. Depósito de Investigación de la Universidad de Sevilla instname:Universidad de Sevilla (US) |
| instname_str |
Universidad de Sevilla (US) |
| reponame_str |
idUS. Depósito de Investigación de la Universidad de Sevilla |
| collection |
idUS. Depósito de Investigación de la Universidad de Sevilla |
| repository.name.fl_str_mv |
|
| repository.mail.fl_str_mv |
|
| _version_ |
1869414853223907328 |
| score |
15,812429 |