Admin actions post to /livewire/update, which a path-scoped guard skips — an operator session could drive admin components through a PUBLIC hostname despite ADMIN_HOSTS. The restriction is now registered as Livewire-persistent middleware and listed on the admin route group, so Livewire re-applies it from the component snapshot. Proven by replaying a snapshot taken from the real rendered page: identical payload -> 404 on a public host, 200 on the allowed host (positive control, so the test cannot pass for the wrong reason). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Admin | ||
| Auth | ||
| Provisioning | ||
| BillingTest.php | ||
| ComponentTest.php | ||
| DashboardTest.php | ||
| ExampleTest.php | ||
| ImpersonationTest.php | ||
| OperatorInPortalTest.php | ||
| PortalTabsTest.php | ||
| SeatsTest.php | ||
| SettingsTest.php | ||
| WelcomeTest.php | ||