Source: tests/api/unit/ApiAnonymousAccessTest.php · 120 lines, ~394 statements · namespace: (global) · `declare(strict_types=1)`: no
ApiAnonymousAccessTest
Regression tests (F1) locking in the anonymous-access fix: public endpoints return 200 without authentication while write endpoints still reject anonymous callers.
All public controllers set $this→requiresAuth = false before parent::__construct(), so GET index() works without any auth header. Write actions re-assert $this→requiresAuth = true inside the action and then enforce permissions via ApiAuth::hasPermission() — an anonymous caller fails that check and receives 403 FORBIDDEN. (The base ApiController's 401 branch only fires when requiresAuth is true at construction time, so anonymous writes are 403, not 401.)
| Mode | Target | Line |
|---|---|---|
require | require_once DIR . '/../ApiTestCase.php'; | 20 |
require | require_once DIR . '/../fixtures/ApiDataFixture.php'; | 21 |