← Back to articles
Technology

Boundary Testing: Where Bugs Actually Hide

Boundary Testing: Where Bugs Actually Hide

Where to Spend Limited Testing Time

No project has enough time to test every input and every sequence of actions. Given that constraint, the real question in test design is where to spend your limited time. Experience shows that most bugs that actually reach production aren't triggered by "normal" input β€” they show up at the edges: character limits, empty fields, rapid double-clicks, the browser back button, and slow networks. These are exactly the areas developers tend to overlook, and the ones test plans often skip too.

A Strategy: Focus on Boundaries and Edge Cases

Instead of trying to cover every combination, decide up front where things are most likely to break, and concentrate there. In practice, narrowing your scope to the following five patterns catches a disproportionate share of bugs for the effort involved.

1. Character Boundaries

  • Emoji and surrogate pairs (4-byte characters like πŸŽ‰)
  • Combining characters and zero-width characters that change length after Unicode normalization
  • Whether SQL special characters (', ", ;) are accepted as-is
  • Layout breakage in right-to-left languages such as Arabic

2. Length Boundaries

  • Empty strings and whitespace-only input
  • The database column's max length, and "max length + 1 character"
  • Zero, negative numbers, and floating-point values prone to rounding errors

3. Rapid or Duplicate Submissions

  • Double-clicking the submit button
  • Repeated clicks under a slow network
  • Sending the same request from two tabs at once

4. Back Navigation

  • Using the browser back button after form submission, then resubmitting
  • Closing a tab and continuing the same session from another tab
  • Repeatedly navigating back and forward during a page transition

5. Timeouts and Slow Connections

  • Throttling the network to 3G speed in Chrome DevTools
  • The user taking another action while an API response is still pending
  • A session token expiring mid-operation

Real Failures Found This Way

In one signup form, entering a 4-byte emoji character in the name field caused a mismatch between the frontend's JavaScript character count and the database's validation. The frontend passed the "20 characters or fewer" check, but the database insert failed. The root cause: JavaScript's .length counts a surrogate pair as two characters, while the database validation counted correctly. This bug only surfaced because a length boundary and a character-type edge case overlapped.

In another case, double-clicking a checkout button created two duplicate orders. Normal test scripts, which click once, never caught it β€” it only showed up once "rapid double-click" was added as an explicit test case.

Turning This Into a Test Plan

Even applying these five patterns as a plain checklist against each feature has real value.

  1. List every field that accepts user input
  2. Apply character-type and length boundaries to each field
  3. Always test "rapid clicks" and "back navigation" against irreversible actions like payment or submission
  4. Apply timeout scenarios to any flow that depends on an external API
  5. If time remains, expand into other combinations

You don't need every pattern on every feature. Prioritizing irreversible actions (payment, deletion, submission) and externally visible input (names, comment fields) lets you catch the highest-impact bugs first, even under tight deadlines.

Bugoon in Practice

Bugs found through boundary testing tend to have unusual reproduction conditions, which makes the information captured at report time especially important. Bugoon's widget lets a reporter annotate a screenshot of the exact screen and automatically records the preceding steps before the report is sent. A reproduction condition as specific as "signed up with an emoji in the name field, exactly 20 characters" is much easier to convey when a screenshot and step history are attached, rather than described from memory. Reports flow directly into a GitHub Issue, so even small bugs caught during boundary testing stay inside the same fix pipeline instead of getting lost in a separate tracker.

Streamline bug reporting for your team.

Bugoon is free to get started. Add one line of code to your site and transform how your team handles bugs.

Get Started