White-Box Testing
- In Turkish
- Beyaz Kutu Testi
In short
White-box testing designs tests from knowledge of the code's internal structure, so that its statements, branches and paths are exercised and checked directly.
What is white-box testing?
Where black-box testing asks whether the software does what the specification says, white-box testing asks whether every part of the code has been run and behaves correctly. The tester reads the implementation and writes tests that take each branch of an if, go through loops zero, one and many times, and trigger each error-handling path.
Coverage measures guide the work. Statement coverage shows which lines ran, branch coverage whether each condition was both true and false, and path coverage whether combinations of branches were taken. Tools such as Istanbul, coverage.py and JaCoCo report these numbers, and mutation testing goes further by checking whether tests notice small deliberate changes to the code.
Most white-box testing is done by developers through unit and integration tests, since they know the code best. It is especially valuable for complex logic, security checks and code where a rarely taken branch, such as a retry after a timeout, could fail silently in production.
A common misconception is that full coverage means the code is correct. Coverage only proves that lines were executed, not that the right results were asserted, and it can't reveal behavior that is missing entirely because a requirement was never implemented. White-box tests also tend to be tied to the implementation, so they need updating more often when code is refactored.
Key takeaways
- White-box testing uses knowledge of the code to design tests.
- The goal is to exercise statements, branches and paths.
- Coverage tools and mutation testing measure how thorough it is.
- Developers do most of it in unit and integration tests.
- High coverage doesn't prove correctness or catch missing features.
Example
function shippingCost(total, country) {
if (total >= 100) return 0; // branch 1: free shipping
if (country === "TR") return 5; // branch 2: domestic
return 15; // branch 3: international
}
test("free above the threshold", () => expect(shippingCost(100, "DE")).toBe(0));
test("domestic rate", () => expect(shippingCost(99, "TR")).toBe(5));
test("international rate", () => expect(shippingCost(99, "DE")).toBe(15));
// npx jest --coverage → 100% branch coverage for shippingCostReaders ask
Who does white-box testing?
Mostly developers, because it requires reading and understanding the code. Security testers also use it when reviewing code for vulnerabilities.
What is branch coverage?
The percentage of decision outcomes, such as both the true and false side of each if statement, that the tests executed. It is stricter and more useful than plain line coverage.
What is gray-box testing?
A mix of the two approaches: tests are designed from the outside like black-box tests, but with partial knowledge of the internals, such as the database schema or architecture, to target likely problems.
Often compared
See also
- Black-Box TestingTesting & Quality, p. 5Black-box testing checks software only through its inputs and outputs, against what it is supposed to do, without looking at or relying on the code inside.
- Test CoverageTesting & Quality, p. 30Test coverage is a metric that measures how much of a program's source code is executed when its automated tests run, usually shown as a percentage.
- Unit TestTesting & Quality, p. 35A unit test is a small, automated check that verifies one function, method, or class behaves correctly in isolation from the rest of the program.
- Mutation TestingTesting & Quality, p. 17Mutation testing measures the quality of a test suite by inserting small deliberate bugs into the code and checking whether the tests fail and catch each one.
- Static AnalysisTesting & Quality, p. 26Static analysis is the automated examination of source code without running it, to find bugs, security vulnerabilities, and quality problems early.
- Integration TestTesting & Quality, p. 12An integration test is an automated test that checks whether several parts of a system, such as code, a database, and an API, work correctly together.
Spotted a mistake or something missing on this page?Suggest an edit