<?xml version="1.0" encoding="UTF-8"?>
<phpunit xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
         xsi:noNamespaceSchemaLocation="vendor/phpunit/phpunit/phpunit.xsd"
         bootstrap="tests/bootstrap.php"
         colors="true"
         failOnWarning="true"
         failOnRisky="true"
         beStrictAboutOutputDuringTests="false"
         cacheDirectory=".phpunit.cache"
>
    <!--
        NFR-43 — the CI gate. Given DEC-07 (no QA engineer), these thresholds are
        contractual, not aspirational: >= 90% on pricing/availability/catering,
        >= 70% overall, build fails below.

        The suite runs against PostgreSQL, never SQLite. SQLite has no
        btree_gist, no exclusion constraints, no daterange and no generated
        stored columns — a green suite on SQLite would say nothing at all about
        FR-39, which is the one invariant this phase exists to prove.
    -->
    <testsuites>
        <testsuite name="Unit">
            <directory>tests/Unit</directory>
        </testsuite>
        <testsuite name="Feature">
            <directory>tests/Feature</directory>
        </testsuite>
    </testsuites>
    <source>
        <include>
            <directory>app</directory>
        </include>
        <exclude>
            <directory>app/Console/Commands/SpikeAttemptHold.php</directory>
        </exclude>
    </source>
    <php>
        <env name="APP_ENV" value="testing"/>
        <env name="APP_MAINTENANCE_DRIVER" value="file"/>
        <env name="BCRYPT_ROUNDS" value="4"/>
        <env name="CACHE_STORE" value="array"/>
        <env name="DB_CONNECTION" value="pgsql"/>
        <env name="MAIL_MAILER" value="array"/>
        <env name="QUEUE_CONNECTION" value="sync"/>
        <env name="SESSION_DRIVER" value="array"/>
        <!-- The breach-list check is a live HTTPS call; off by default in tests. -->
        <env name="AUTH_PASSWORD_BREACH_CHECK" value="false"/>

        <!--
            SSR off, because the suite was inheriting `INERTIA_SSR_ENABLED=true` from
            `.env` and there is no render worker in a test run.

            Every Class A document render therefore opened a socket to a worker that was
            not listening and waited for the timeout. It is not a small cost: a 410 test
            making two requests took 9.5s against 0.7s for the same class's POST-only
            tests, and the difference is entirely the connect timeouts on the error page's
            render.

            The tests that are *about* SSR are unaffected — `SsrDegradationTest`,
            `SsrRoutingTest`, `SsrBreakerTest` and `PageCacheTest` each set
            `inertia.ssr.enabled` themselves, because what they assert depends on it. This
            only stops every *other* test paying for a feature it is not testing.
        -->
        <env name="INERTIA_SSR_ENABLED" value="false"/>

        <!--
            No Redis, on purpose - the same inheritance problem as SSR above.

            `cache.full_page.store_name` defaults to `redis`, and FullPageCache probes it
            and switches itself off when it cannot connect. Until predis became a
            dependency no test could connect, so the page cache was silently off in the
            whole suite. With a developer's Redis running (setup-local-services.ps1) it
            came on: the paratest workers shared one cache, a page stored by one test was
            served as a HIT to another, and 125 tests failed on "The response is not a
            view". CI has no Redis at all, so this also makes both agree. Tests about the
            page cache set their own store (`array`), as they already did.

            A dead port and a short timeout, because a refused connect waits ~2 s on
            Windows.
        -->
        <env name="REDIS_PORT" value="1"/>
        <env name="REDIS_TIMEOUT" value="0.2"/>
        <env name="MEILISEARCH_HOST" value=""/>

        <!--
            Debug off, so an expected 4xx does not build a debug error page.

            Laravel's exception renderer reads source files and assembles stack frames for
            every handled abort, and this suite asserts hundreds of 403s, 404s and 419s.
            A test that wants the exception rather than the response still has
            `withoutExceptionHandling()`, and PHPUnit prints the exception either way — so
            nothing about diagnosing a failure gets worse.
        -->
        <env name="APP_DEBUG" value="false"/>
    </php>
</phpunit>
