integration-testing

A testing guide for checking that separate parts of an application work together, including login, protected pages, APIs, and data flow.

In plain words
What is it for?
It is for testing authentication end to end, checking administrator access, sending real requests to API endpoints, and confirming that data and response formats match.
Why use it?
It catches failures between services and real application boundaries before later features depend on them.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/gosha70/code-copilot-team/integration-testing
Clone the repo
git clone --depth 1 https://github.com/gosha70/code-copilot-team

Made for: Cursor.

Per session 20 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 926 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00020 $0.00926
Opus 5 $0.00010 $0.00463
Sonnet 5 $0.00004 $0.00185
Haiku 4.5 $0.00002 $0.00093

Measured yesterday against content hash d2fe66e6167e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

integration-testing scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

curl -s -o /dev/null -w "%{http_code}" http://localhost:3000/login
adapters/cursor/.cursor/rules/integration-testing.mdc · 107 lines

How it starts

The opening of the file, as written. The whole thing — 107 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Integration Testing Protocol

Rules for verifying that cross-cutting features work before building on top of them.

Auth Must Be Verified Before Feature Development

Authentication is the most common source of cascading failures in multi-agent builds. Auth issues that go undetected compound as more features depend on protected routes.

After implementing auth (any strategy):

  1. Verify the auth flow end-to-end:

    • Login succeeds with valid credentials
    • Login fails with invalid credentials
    • Protected routes redirect unauthenticated users
    • Session persists across page navigation
    • Logout clears the session
  2. Verify admin access (if applicable):

    • Admin routes are accessible only to admin users
    • Non-admin users are redirected or shown a 403
    • The admin check works with the actual session token, not a mock
  3. Do not build features on top of auth until the flow is verified. Building protected pages before confirming auth works leads to multi-session debugging cycles.

API Contract Verification

After implementing backend services or API routes:

  1. Test each endpoint with a real request (not just type-checking).
  2. Verify that request/response shapes match the contracts defined in the plan.
  3. Verify error responses (404, 400, 401, 500) return the expected format.
  4. If using an ORM, verify that database queries return the expected data shape.

Frontend-Backend Integration

After connecting frontend to backend:

  1. Verify that UI components call the correct API endpoints.
  2. Verify that loading states, error states, and empty states all render.
  3. Verify that mutations (create, update, delete) reflect in the UI without a page refresh.
  4. Check the browser console for errors — especially hydration mismatches in SSR frameworks.

Cross-Agent Integration

When multiple agents have worked in parallel:

  1. Check shared types — do both sides agree on the shape of shared data?
  2. Check imports — are agents importing from the correct paths?
  3. Check database state — if one agent created schema and another wrote queries, do they match?
  4. Run the full app — not just individual modules.

Read the full file on GitHub · 107 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 107 lines · 20 tokens per session scan A d2fe66e6167e

Subscribe to this mod's changes

integration-testing is a cursor rule published in the GitHub repository gosha70/code-copilot-team (6 stars, last pushed 2d ago), licensed MIT. It adds 20 tokens to every session and 926 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.