CI

CI, reports, and VCR

Same snapapi you run locally. Install in a venv, point it at the suites, publish the reports.

Example job

python3 -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"
snapapi tests \
  --report junit:report.xml \
  --report html:report.html \
  --safe-url

Exit 0 when every test passed, 1 when a test failed, 2 on parse or usage errors. Upload report.xml to the CI test reporter and report.html as a build artifact.

Report kinds

FlagOutput
--report json:report.jsonMachine-readable suite/test payload, including request summaries.
--report junit:report.xmlJUnit XML (testsuites / testcase). Failures carry the SnapAPI error message.
--report html:report.htmlSelf-contained HTML with redacted request/response bodies.

Repeat --report to write more than one format in a single run.

VCR cassettes

Cassettes live under .snapapi/cassettes/. Keys include method, path, and (by default) sorted query string, Content-Type / Accept, and body.

snapapi tests/fixtures/offline.snaptest --mode record
snapapi tests/fixtures/offline.snaptest --mode replay
snapapi tests/fixtures/offline.snaptest --mode record-on-miss

Override identity fields with --vcr-match authorization,query or suite OPTIONS: {"VCR-MATCH": ["query","body","accept","authorization"]}. Replay restores Set-Cookie onto the session. Commit cassettes for offline CI; do not commit secrets — HTML reports and dumps redact sensitive fields, but review cassette JSON before you push.

--safe-url

--safe-url blocks private and metadata hosts (loopback, RFC1918, link-local, cloud metadata). Use it in CI when ${URL} comes from the environment. Pair it with a public API, or a mock the job starts:

snapapi mock examples/hello/mock.json --port 8765 &
snapapi examples/hello/hello.sapi

tests/recommended.snaptest isn’t this hello mock. It wants ${BASE_URL} and extra routes — pytest fills those in this repo. Don’t pair it with tests/fixtures/mock.json (that file only serves GET /ping).

Local mocks are private URLs, so skip --safe-url unless you also pass --allow-private-urls. For third-party APIs in CI, --safe-url is the right default.

This repository

Our own CI uses a local mock and doesn’t call public APIs. There’s a checked-in cassette for the offline fixture. For your suites: snapapi lint, then snapapi with --mode replay if you commit cassettes.