fix: statisc
This commit is contained in:
@@ -0,0 +1,59 @@
|
||||
<?php
|
||||
|
||||
namespace Tests\Feature;
|
||||
|
||||
use Illuminate\Foundation\Testing\RefreshDatabase;
|
||||
use PHPUnit\Framework\Attributes\Test;
|
||||
use Tests\TestCase;
|
||||
|
||||
class PanelHostMiddlewareTest extends TestCase
|
||||
{
|
||||
use RefreshDatabase;
|
||||
|
||||
#[Test]
|
||||
public function empty_allowlist_allows_any_host(): void
|
||||
{
|
||||
config([
|
||||
'coruna.panel.admin_hosts' => [],
|
||||
'coruna.panel.agent_hosts' => [],
|
||||
]);
|
||||
|
||||
$this->get('http://anything.example/admin/login')->assertOk();
|
||||
$this->get('http://anything.example/user/login')->assertOk();
|
||||
}
|
||||
|
||||
#[Test]
|
||||
public function admin_panel_rejects_non_allowlisted_host_with_404(): void
|
||||
{
|
||||
config([
|
||||
'coruna.panel.admin_hosts' => ['admin.example.com'],
|
||||
'coruna.panel.agent_hosts' => [],
|
||||
]);
|
||||
|
||||
$this->get('http://admin.example.com/admin/login')->assertOk();
|
||||
$this->get('http://evil.example.com/admin/login')->assertNotFound();
|
||||
// Agent unrestricted when its list is empty.
|
||||
$this->get('http://evil.example.com/user/login')->assertOk();
|
||||
}
|
||||
|
||||
#[Test]
|
||||
public function agent_panel_rejects_non_allowlisted_host_with_404(): void
|
||||
{
|
||||
config([
|
||||
'coruna.panel.admin_hosts' => [],
|
||||
'coruna.panel.agent_hosts' => ['agent.example.com'],
|
||||
]);
|
||||
|
||||
$this->get('http://agent.example.com/user/login')->assertOk();
|
||||
$this->get('http://evil.example.com/user/login')->assertNotFound();
|
||||
$this->get('http://evil.example.com/admin/login')->assertOk();
|
||||
}
|
||||
|
||||
#[Test]
|
||||
public function host_match_is_case_insensitive(): void
|
||||
{
|
||||
config(['coruna.panel.admin_hosts' => ['Admin.Example.COM']]);
|
||||
|
||||
$this->get('http://admin.example.com/admin/login')->assertOk();
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user