Source: tests/api/unit/ProtectedPostApiControllerTest.php · 124 lines, ~400 statements · namespace: (global) · `declare(strict_types=1)`: no
ProtectedPostApiController Test
Unit tests for Scriptlog\Controller\Api\ProtectedPostApiController driven through the subprocess runner (ApiTestCase::runController). Controller actions terminate the process via ApiResponse::send(), so each action runs in an isolated PHP process against the seeded test database.
Auth: both actions are public (requiresAuth=false at construction).
Coverage note: unlock()/verify() read the password from the JSON request body (ApiController::getJsonBody() reads php:input). The CLI runner provides an empty php:input, so the guard branches (400 for a missing post ID and missing password) are asserted here; the password-verification branches (401 incorrect password / 200 unlock) require an HTTP request with a JSON body and a password-protected post, which is out of reach of the unit harness and deferred to an HTTP-level integration test.
| Mode | Target | Line |
|---|---|---|
require | require_once DIR . '/../ApiTestCase.php'; | 23 |
require | require_once DIR . '/../fixtures/ApiDataFixture.php'; | 24 |