Admin actions post to /livewire/update, which a path-scoped guard skips — an operator session could drive admin components through a PUBLIC hostname despite ADMIN_HOSTS. The restriction is now registered as Livewire-persistent middleware and listed on the admin route group, so Livewire re-applies it from the component snapshot. Proven by replaying a snapshot taken from the real rendered page: identical payload -> 404 on a public host, 200 on the allowed host (positive control, so the test cannot pass for the wrong reason). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| AdminConsoleTest.php | ||
| AdminHostRestrictionTest.php | ||
| AdminSettingsTest.php | ||
| DatacenterTest.php | ||
| HostManagementTest.php | ||
| MaintenanceTest.php | ||
| ProvisioningActionsTest.php | ||
| RbacTest.php | ||