Admin actions post to /livewire/update, which a path-scoped guard skips — an operator session could drive admin components through a PUBLIC hostname despite ADMIN_HOSTS. The restriction is now registered as Livewire-persistent middleware and listed on the admin route group, so Livewire re-applies it from the component snapshot. Proven by replaying a snapshot taken from the real rendered page: identical payload -> 404 on a public host, 200 on the allowed host (positive control, so the test cannot pass for the wrong reason). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Actions | ||
| Console | ||
| Http | ||
| Livewire | ||
| Models | ||
| Notifications | ||
| Providers | ||
| Provisioning | ||
| Services | ||