Skip to content
Back to skills

Api Platform Tests

ASecurity

Test API Platform resources with ApiTestCase; assert collections, items, filters, JSON schema, and authentication

  • 221 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added August 31, 2026
developmentphpshellbashrailstestingapidatabase

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 6, 2026

npx -y skills add dev-toolings/superpowers-symfony --skill api-platform-tests --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Api Platform Tests?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Api Platform Tests
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dev-toolings-api-platform-tests/badge)](https://www.skillsdirectory.com/skills/dev-toolings-api-platform-tests)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: api-platform-tests
description: Test API Platform resources with ApiTestCase; assert collections, items, filters, JSON schema, and authentication
capabilities: [read, search, edit, shell]
tags: [api-platform, testing]
# projected by `bun run build` — do not edit by hand
allowed-tools:
  - Read
  - Glob
  - Grep
  - Write
  - Edit
  - Bash
---

# Api Platform Tests (Symfony)

## Use when
- Writing functional tests for API Platform endpoints: collection, item, create, update, delete.
- Asserting validation errors (422) and access control (401, 403).
- Checking filters, pagination, or the JSON schema of responses.
- Setting up a clean database and test data for API tests.

## Default workflow
1. Extend `ApiTestCase` and seed data with Foundry factories (`createOne`, `createMany`).
2. Reset state with `#[ResetDatabase]` and the `Factories` trait, with DAMA rolling back each test.
3. Call `static::createClient()->request()` and assert the status code, content type, and `assertJsonContains()`.
4. Authenticate with `auth_bearer` and cover the anonymous, owner, and other-user cases.
5. Assert `member` and `totalItems` for filters and pagination (`hydra:`-prefixed only with `hydra_prefix: true`).
6. Assert the shape with `assertMatchesResourceItemJsonSchema()` and `assertMatchesResourceCollectionJsonSchema()`.

## Guardrails
- Send `PATCH` with the `application/merge-patch+json` content type.
- `#[ResetDatabase]` needs PHPUnit 10+ and Foundry 2.9: use the `ResetDatabase` trait on PHPUnit 9.
- Cover the failure paths too: 404, 422, 401, 403. A type error on a constrained property is 422 in 5.0 but 400 in 4.4 and earlier.
- Read the configured items per page rather than hardcoding a page size in assertions.

## Progressive disclosure
- Use this file for execution posture and risk controls.
- Open references when deep implementation details are needed.

## Output contract
- The test classes added and the endpoints they cover.
- Factories and reset strategy used.
- Test run output, including the failure paths.

## References
- `reference.md`

Files in this skill

  • SKILL.md1.2 KB
  • reference.md10.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…