Quality Assurance is important in identifying issues before they impact your customers and, depending on the nature of your project, there are several different types of quality assurance testing that youโre going to want to consider as part of your integration with Auth0:
- Is your application easy to understand and use, even by those with a disability?
- Does your application need to work across various different browsers and devices?
- Does your application need to work in multinational and/or international environments?
- How will your application perform when subjected to unexpected production loads?
- How can you ensure your application is safe from security-related vulnerabilities?
Auth0ย Universal Loginย and associated UI widgets (such asย Lock) have already been designed and built following usability and accessibility best practices, and provide tested out-of-box support for a whole host ofย browsers and devices. Support forย internationalizationย (I18N) is also provided out-of-box, with built-in extensibility designed for custom multi-language and localization (L10N) situations.
To ensure functional requirements are met and unexpected events are handled correctly, guidance is provided for testing theย integrationย between your application(s) and Auth0, and forย unit testingย individual extensibility modules (such asย Rules,ย Hooks, and Custom Database scripts). Guidance is also provided regarding Auth0โsย penetration testing policyย to help when testing for security vulnerability, and also howย Mockย testing can be leveraged in conjunction with ourย load testing policyย to help ensure your application(s) perform under unexpected load.
Unit testing
The objective of unit testing is to test individual units of code. If you create custom code within Auth0 in the form of Rules, Hooks, and/or Custom DB scripts, you should consider use a testing framework (such asย Mocha) to test your code. Companies who have been most successful with Auth0 have found it useful to execute these unit tests prior toย automatically deployingย Auth0 tenant configuration and collateral.
Integration testing
It is a recommended best practice that you set up different tenants for development, testing, and production as discussed in Architecture guidance forย SDLC support. Auth0 allows you to configure variables that are available from within customย extensibility; these can be thought of as environment variables for your Auth0 tenant. Rather than hard code references that change when moving code between development, test, and production environments, you can use a variable name that is configured in the tenant and referenced by the custom extensibility code. This makes it easier for the same custom code to function, without changes, in different tenants as the code can reference variables which will be populated with tenant-specific values at execution time:
- For use of variables in Rules, see how toย configure values
- For use of variables in Hooks, see how to configureย secretsย in the editor
- For use of variables in Actions, see Explore Flows and Triggers
- For use of variables in Custom DB Scripts, see theย configuration parameters
We recommend using variables to contain tenant-specific values as well as any sensitive secrets that should not be exposed in your custom code. If your custom code is deployed in GitHub, then using a tenant-specific variable avoids exposure of sensitive values via your GitHub repository.
Test automation
You can automate your overall build process by incorporating deployment automation as well as test automation. This can be used to deploy new versions of configuration and/or custom code to Auth0 and execute automated tests. If the tests uncover any failures, the deployment automation capabilities can be used to revert to the last working version. For further information, see theย deployment automation guidanceย provided.
Mock testing
In a balance between Auth0โsย load testing policyย and the desire to load test, it is common practice among Auth0โs customers to mock out Auth0โs endpoints. This is a valuable practice in order to ensure that your application works with your expected interfaces without having to restrict your testing, and tools such asย MockServer,ย JSON Serverย or evenย Postmanย can be used to assist.
Project Planning Guide
We provide planning guidance in PDF format that you can download and refer to for details about our recommended strategies.
B2C IAM Project Planning Guide