Tests that /actuator/health is accessible without credentials and /actuator/env requires authentication — permanent regression guards against CVE-2026-40976-class Actuator filter chain bypass bugs. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>