60 lines
1.7 KiB
PHP
60 lines
1.7 KiB
PHP
<?php
|
|
|
|
namespace Tests\Feature;
|
|
|
|
use Illuminate\Foundation\Testing\RefreshDatabase;
|
|
use PHPUnit\Framework\Attributes\Test;
|
|
use Tests\TestCase;
|
|
|
|
class PanelHostMiddlewareTest extends TestCase
|
|
{
|
|
use RefreshDatabase;
|
|
|
|
#[Test]
|
|
public function empty_allowlist_allows_any_host(): void
|
|
{
|
|
config([
|
|
'coruna.panel.admin_hosts' => [],
|
|
'coruna.panel.agent_hosts' => [],
|
|
]);
|
|
|
|
$this->get('http://anything.example/admin/login')->assertOk();
|
|
$this->get('http://anything.example/user/login')->assertOk();
|
|
}
|
|
|
|
#[Test]
|
|
public function admin_panel_rejects_non_allowlisted_host_with_404(): void
|
|
{
|
|
config([
|
|
'coruna.panel.admin_hosts' => ['admin.example.com'],
|
|
'coruna.panel.agent_hosts' => [],
|
|
]);
|
|
|
|
$this->get('http://admin.example.com/admin/login')->assertOk();
|
|
$this->get('http://evil.example.com/admin/login')->assertNotFound();
|
|
// Agent unrestricted when its list is empty.
|
|
$this->get('http://evil.example.com/user/login')->assertOk();
|
|
}
|
|
|
|
#[Test]
|
|
public function agent_panel_rejects_non_allowlisted_host_with_404(): void
|
|
{
|
|
config([
|
|
'coruna.panel.admin_hosts' => [],
|
|
'coruna.panel.agent_hosts' => ['agent.example.com'],
|
|
]);
|
|
|
|
$this->get('http://agent.example.com/user/login')->assertOk();
|
|
$this->get('http://evil.example.com/user/login')->assertNotFound();
|
|
$this->get('http://evil.example.com/admin/login')->assertOk();
|
|
}
|
|
|
|
#[Test]
|
|
public function host_match_is_case_insensitive(): void
|
|
{
|
|
config(['coruna.panel.admin_hosts' => ['Admin.Example.COM']]);
|
|
|
|
$this->get('http://admin.example.com/admin/login')->assertOk();
|
|
}
|
|
}
|