Currently, only routes that do not contain resources but require authentication, are tested from the perspective of an unauthenticated user. This could be expanded to all routes that require authentication – including those that contain resources.