Recorded Traffic → Integration Tests
Turn real traffic into a repeatable test suite. Three inputs are understood: a HAR export (browser dev tools → "Save all as HAR", Postman, Charles) — each request is replayed and the recorded status, Content-Type and the shape of the JSON response (types and always-present keys, merged across array items — never the values) are asserted; curl commands (one or many, "Copy as cURL") — a 2xx is asserted; and an access log (Apache/Nginx common or combined format) — only safe GET requests are replayed, as smoke tests of the most requested URLs.
Recorded traffic is full of secrets, so none is copied into the code: sensitive headers (Authorization, Cookie, API keys), query parameters and JSON/form body fields (password, token, secret, …) become environment-variable lookups (TEST_AUTHORIZATION, TEST_COOKIE, TEST_PASSWORD, …). Requests are replayed in order with their recorded values, so one-time values (CSRF tokens, nonces) and writes may not be repeatable.