client->request('GET', '/api/v1/altcha/challenge'); self::assertSame(200, $this->responseCode()); $body = json_decode($this->client->getResponse()->getContent(), true); self::assertSame('SHA-256', $body['algorithm']); foreach (['challenge', 'salt', 'signature', 'maxnumber'] as $key) { self::assertArrayHasKey($key, $body); } } public function testPublicEndpointBypassesCaptchaWhenDisabled(): void { // ALTCHA_ENABLED is false in test → guard is a no-op, so send-code proceeds // past the captcha check without an `altcha` field (fails later on validation only). $this->client->request( 'POST', '/api/v1/user/send-code', server: ['CONTENT_TYPE' => 'application/json'], content: json_encode(['mobile' => '09123456789']), ); // Not a 422 captcha rejection: either success or a non-captcha error. $body = json_decode($this->client->getResponse()->getContent(), true) ?? []; $code = $body['errors'][0]['code'] ?? null; self::assertNotSame('ERR_CAPTCHA_001', $code); } }