Admin actions post to /livewire/update, which a path-scoped guard skips — an operator session could drive admin components through a PUBLIC hostname despite ADMIN_HOSTS. The restriction is now registered as Livewire-persistent middleware and listed on the admin route group, so Livewire re-applies it from the component snapshot. Proven by replaying a snapshot taken from the real rendered page: identical payload -> 404 on a public host, 200 on the allowed host (positive control, so the test cannot pass for the wrong reason). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| channels.php | ||
| console.php | ||
| web.php | ||