mirror of
https://github.com/InvoiceShelf/InvoiceShelf.git
synced 2026-09-02 13:21:02 +00:00
* refactor: stabilize model identities for domain migration * refactor: extract module platform context * refactor: assign models to domain contexts * refactor: extract ai platform context * refactor: extract storage platform context * refactor: extract mail platform context * refactor: extract pdf platform context * refactor: extract operations platform context * refactor: move installation into operations platform * refactor: extract money domain context * refactor: extract taxation domain context * refactor: extract catalog domain context * refactor: extract metadata domain context * refactor: extract reporting domain context * refactor: extract purchases domain context * refactor: extract receivables domain context * refactor: extract accounts domain context * refactor: complete reporting statement boundary * refactor: extract contacts domain context * refactor: extract sales domain context * refactor: remove legacy application layers * fix: migrate legacy bouncer role identities
53 lines
1.7 KiB
PHP
53 lines
1.7 KiB
PHP
<?php
|
|
|
|
use App\Domains\Accounts\Models\User;
|
|
use Illuminate\Support\Facades\Artisan;
|
|
use Laravel\Sanctum\Sanctum;
|
|
|
|
use function Pest\Laravel\postJson;
|
|
|
|
/**
|
|
* S3 / DigitalOcean Spaces endpoints are admin-supplied and fetched server-side
|
|
* during credential validation, so a private/reserved endpoint must be rejected.
|
|
*/
|
|
beforeEach(function () {
|
|
Artisan::call('db:seed', ['--class' => 'DatabaseSeeder', '--force' => true]);
|
|
Artisan::call('db:seed', ['--class' => 'DemoSeeder', '--force' => true]);
|
|
|
|
$user = User::find(1);
|
|
$this->withHeaders(['company' => $user->companies()->first()->id]);
|
|
Sanctum::actingAs($user, ['*']);
|
|
});
|
|
|
|
test('rejects a doSpaces disk whose endpoint targets a private host', function () {
|
|
postJson('/api/v1/disks', [
|
|
'name' => 'evil-spaces',
|
|
'driver' => 'doSpaces',
|
|
'credentials' => [
|
|
'key' => 'k',
|
|
'secret' => 's',
|
|
'region' => 'nyc3',
|
|
'bucket' => 'b',
|
|
'endpoint' => 'http://169.254.169.254',
|
|
'root' => '/',
|
|
],
|
|
'set_as_default' => false,
|
|
])->assertStatus(422)->assertJsonValidationErrors('credentials.endpoint');
|
|
});
|
|
|
|
test('rejects an s3 disk whose endpoint targets a private host', function () {
|
|
postJson('/api/v1/disks', [
|
|
'name' => 'evil-s3',
|
|
'driver' => 's3',
|
|
'credentials' => [
|
|
'key' => 'k',
|
|
'secret' => 's',
|
|
'region' => 'us-east-1',
|
|
'bucket' => 'b',
|
|
'endpoint' => 'http://10.1.2.3',
|
|
'root' => '/',
|
|
],
|
|
'set_as_default' => false,
|
|
])->assertStatus(422)->assertJsonValidationErrors('credentials.endpoint');
|
|
});
|