1---2name: restassured-core3description: Use when Codex needs to implement, refactor, debug, or extend Rest Assured API tests with JUnit 5, reusable request and response specifications, authentication helpers, DTOs, contract checks, and service-test best practices.4---56# Rest Assured Core78## 1. Preflight9101. Inspect the build file, Java version, test engine, and module boundaries.112. Inspect API documentation, existing contracts, auth flow, and environment variables.123. Read [preflight.md](references/preflight.md) before major changes.1314## 2. Choose the Test Shape15161. Use [service-test-types.md](references/service-test-types.md) to classify the test as smoke, regression, contract, integration, negative, or workflow.172. Read [project-structure.md](references/project-structure.md) before creating new packages.183. Use JUnit 5 patterns from [junit5-patterns.md](references/junit5-patterns.md).194. Use build guidance from [maven-and-gradle.md](references/maven-and-gradle.md).205. Decide whether the suite is `runtime-aligned`, `contract-enforcement`, or `mixed` before writing assertions.2122## 3. Implement the Backbone23241. Build shared request and response specs from [request-response-specs.md](references/request-response-specs.md).252. Centralize auth logic with [authentication.md](references/authentication.md).263. Add semantic assertions using [validation-and-assertions.md](references/validation-and-assertions.md).274. Add schema or contract checks only when they increase signal; use [schema-and-contract-validation.md](references/schema-and-contract-validation.md).285. Build deterministic test data with [test-data-management.md](references/test-data-management.md).296. In `runtime-aligned` mode, assert the live behavior in executable tests and route discrepancies to `../documentation/contract-mismatches/SKILL.md`.307. In `contract-enforcement` mode, keep assertions aligned to the specification and tag the tests so drift is visible as an explicit contract failure.318. In `mixed` mode, keep runtime-aligned regression tests separate from contract-enforcement checks by tag, package, or class naming.3233## 4. Add Service-Test Details34351. Read [testcontainers-and-wiremock.md](references/testcontainers-and-wiremock.md) before introducing containers or stubs.362. Read [observability-and-redaction.md](references/observability-and-redaction.md) before enabling request or response logging.373. Read [security-negative-testing.md](references/security-negative-testing.md) for authz, authn, and abuse cases.384. Read [graphql-and-file-upload.md](references/graphql-and-file-upload.md) for GraphQL or multipart endpoints.395. Read [xml-and-soap-payloads.md](references/xml-and-soap-payloads.md) for XML or SOAP payload handling.406. Read the framework recipe that matches the repo: [framework-spring-boot.md](references/framework-spring-boot.md), [framework-quarkus.md](references/framework-quarkus.md), or [framework-micronaut.md](references/framework-micronaut.md).4142## 5. Run and Debug43441. Run the narrowest relevant test first.452. Use [debugging.md](references/debugging.md) for triage.463. Use [error-index.md](references/error-index.md) when a common failure pattern appears.474. If a failure reveals contract drift, capture the raw request, raw response metadata, and affected contract path before changing assertions.485. When a contract-enforcement test fails because the runtime drift is already known, preserve the failing evidence and link it to the mismatch artifact instead of muting the test silently.4950## 6. Examples51521. Input: `Implement POST /orders negative tests from the approved coverage plan.`53 Output: Add `OrdersApiTest`, shared specs, data builders, and explicit `400`, `401`, `403`, `409`, and `422` assertions.542. Input: `Refactor these duplicated given/when/then chains.`55 Output: Extract request and response specs plus auth support before changing test intent.563. Input: `The OpenAPI says JSON but the live 404 returns XML.`57 Output: Keep the executable test aligned to the live XML response, then document the contract mismatch separately.584. Input: `Keep strict contract checks, but do not break the main regression suite.`59 Output: Put the contract-enforcement assertions in a separate tagged slice and keep the runtime-aligned suite stable.6061## 7. Troubleshooting62631. Problem: The suite uses static `RestAssured.baseURI` everywhere.64 Fix: Move configuration into request specs or JUnit lifecycle setup.652. Problem: Tests pass only when run in order.66 Fix: Isolate data setup and cleanup per test or per fixture.673. Problem: Logs expose secrets.68 Fix: Add redaction filters and restrict full logging to failures.694. Problem: The contract and runtime disagree on status, content type, or payload shape.70 Fix: Treat the live runtime as the source for executable assertions, then create a mismatch record instead of forcing the test to match the contract.715. Problem: The user needs both regression stability and strict spec conformance.72 Fix: Split the suite into runtime-aligned and contract-enforcement slices instead of forcing one assertion mode to do both jobs.