Assert a forbidden (403) response
Medium70 pts~25 min
- 403 Forbidden
- Role-based access
Practice app · Acme REST API
A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.
Your starter code already declares BASE_URL — call the API relative to it.
Objective
Show that an authenticated viewer is forbidden from an admin-only resource while an admin is allowed.
Your task
- 1Get a token for the viewer fixture (viewer@target.dev / Viewer@123) via POST BASE_URL + "/auth/token".
- 2GET BASE_URL + "/admin/reports" with the viewer token → assert 403 and error.code "FORBIDDEN".
- 3Repeat with an admin token (qa@target.dev / Test@123) → assert 200.
Acceptance criteria
- GET /admin/reports returns 403 for the viewer
- GET /admin/reports returns 200 for the admin
- At least 2 assertions pass
Fixtures
- apiKey
- tqa_live_key_123
- basicUser
- admin
- basicPassword
- secret
- username
- qa@target.dev
- password
- Test@123
API testing · API Testing · Authorization & negative testing