This is an old revision of the document!
Table of Contents
tests/api/unit/ApiAnonymousAccessTest.php
Source: tests/api/unit/ApiAnonymousAccessTest.php · 120 lines, ~394 statements · namespace: (global) · `declare(strict_types=1)`: no
ApiAnonymousAccessTest
Regression tests (F1) locking in the anonymous-access fix: public endpoints return 200 without authentication while write endpoints still reject anonymous callers.
All public controllers set $this→requiresAuth = false before parent::__construct(), so GET index() works without any auth header. Write actions re-assert $this→requiresAuth = true inside the action and then enforce permissions via ApiAuth::hasPermission() — an anonymous caller fails that check and receives 403 FORBIDDEN. (The base ApiController's 401 branch only fires when requiresAuth is true at construction time, so anonymous writes are 403, not 401.)
Includes
^ Mode ^ Target ^ Line ^ | ''require'' | ''require_once __DIR__ . '/../ApiTestCase.php';'' | 20 | | ''require'' | ''require_once __DIR__ . '/../fixtures/ApiDataFixture.php';'' | 21 |
