e.g. if a method is private, it's not tested.
that's the usual way when full reliability is not worth the dev time, or when devs think functional tests only are enough but still want a tap on the back for having unit tests and coverage numbers.
in their case it's the later as you can see for: "Controller tests also exercise a lot of the code paths in your application"
classical functional tests being called unit tests excuse. not that functional is better or worse, but correct names are better no matter what.