CluPilotCloud/app/Providers
nexxo f5f4d2a8cd fix(security): close the Livewire bypass of the admin host restriction
Admin actions post to /livewire/update, which a path-scoped guard skips — an
operator session could drive admin components through a PUBLIC hostname despite
ADMIN_HOSTS. The restriction is now registered as Livewire-persistent middleware
and listed on the admin route group, so Livewire re-applies it from the
component snapshot.

Proven by replaying a snapshot taken from the real rendered page: identical
payload -> 404 on a public host, 200 on the allowed host (positive control, so
the test cannot pass for the wrong reason).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-25 20:50:22 +02:00
..
AppServiceProvider.php fix(security): close the Livewire bypass of the admin host restriction 2026-07-25 20:50:22 +02:00
FortifyServiceProvider.php fix(auth): scope registration throttle to its own route (per-IP), not all Fortify endpoints 2026-07-25 18:41:30 +02:00