Heading image for post: Test with a Sign In Backdoor


Test with a Sign In Backdoor

Profile picture of Paul Elliott

Did you know that almost every scenario in your acceptance test suite has to sign the user in? Did you know that you are crazily overtesting your sign in page as a result? It doesn't have to be this way.

Typically a login step looks something like this:

Given /^I am signed in$/ do
  visit '/sign_in'
  fill_in 'Email', with: user.email
  fill_in 'Password', with: 'password'
  click_button 'Sign In'

It looks reasonable but every single scenario is requesting and rendering the same page, filling out the same fields, and submitting them. Signing in through the browser is necessary to establish the session, but it doesn't need to be this painful. You can implement a backdoor to take this down to a single page request with no rendering. Even better, you can include it in features/support so you don't open yourself up to any security vulnerabilities.


class UserSessionsController
  def backdoor
    redirect_to :root

MyRailsApp::Application.routes.tap do |routes|
  routes.disable_clear_and_finalize = true
  routes.draw do
    match 'backdoor', to: 'user_sessions#backdoor'

Then you can update your step to look like this:

module SessionStepMethods
  def sign_in(user)
    visit "/backdoor?email=#{user.email}"

Given /^I am signed in$/ do

If you have 500 scenarios in your suite, you just saved 500 full page requests. Great work!

More posts about Ruby Development

  • Adobe logo
  • Barnes and noble logo
  • Aetna logo
  • Vanderbilt university logo
  • Ericsson logo

We're proud to have launched hundreds of products for clients such as LensRentals.com, Engine Yard, Verisign, ParkWhiz, and Regions Bank, to name a few.

Let's talk about your project