mirror of
https://github.com/HolgerHatGarKeineNode/einundzwanzig-app.git
synced 2026-06-11 02:50:29 +00:00
✨ **Enhance input validation and error handling across APIs**
- 🛠️ Refactored controllers to utilize `FiltersNumericIds` concern, ensuring secure numeric ID filtering and avoiding type-sensitive errors in queries. - ➕ Added feature tests to validate robust input hardening for non-numeric or malformed query parameters (`user_id`, `selected[]`). - 🔒 Introduced `PublicPropertyNotFoundException` handling in Livewire, returning 400 for invalid property probes and suppressing unnecessary log entries. - ❌ Updated `MeetupEventController` to handle invalid date formats gracefully, aborting with a 400 response instead of 500. - ✅ Expanded exception handling pipeline for enhanced resilience against malformed input, bot noise, and exploitable probes.
This commit is contained in:
@@ -2,6 +2,7 @@
|
||||
|
||||
namespace App\Http\Controllers\Api;
|
||||
|
||||
use App\Http\Controllers\Api\Concerns\FiltersNumericIds;
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Http\Requests\Api\StoreCityRequest;
|
||||
use App\Http\Requests\Api\UpdateCityRequest;
|
||||
@@ -20,6 +21,8 @@ use Symfony\Component\HttpFoundation\Response;
|
||||
#[Group(name: 'Stammdaten', weight: 5)]
|
||||
class CityController extends Controller
|
||||
{
|
||||
use FiltersNumericIds;
|
||||
|
||||
/**
|
||||
* Städte auflisten und durchsuchen
|
||||
*
|
||||
@@ -40,8 +43,7 @@ class CityController extends Controller
|
||||
)
|
||||
->when(
|
||||
$request->exists('selected'),
|
||||
fn (Builder $query) => $query->whereIn('id',
|
||||
$request->input('selected', [])),
|
||||
fn (Builder $query) => $query->whereIn('id', $this->numericIds($request)),
|
||||
fn (Builder $query) => $query->limit(10)
|
||||
)
|
||||
->get();
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
<?php
|
||||
|
||||
namespace App\Http\Controllers\Api\Concerns;
|
||||
|
||||
use Illuminate\Http\Request;
|
||||
|
||||
trait FiltersNumericIds
|
||||
{
|
||||
/**
|
||||
* Reduziert einen Query-Parameter auf seine numerischen Werte als Integer-Liste.
|
||||
*
|
||||
* Schuetzt typsensitive whereIn('id', ...)-Klauseln vor nicht-numerischer Eingabe.
|
||||
*
|
||||
* @return array<int, int>
|
||||
*/
|
||||
protected function numericIds(Request $request, string $key = 'selected'): array
|
||||
{
|
||||
return $request->collect($key)
|
||||
->filter(fn ($id) => is_numeric($id))
|
||||
->map(fn ($id) => (int) $id)
|
||||
->values()
|
||||
->all();
|
||||
}
|
||||
}
|
||||
@@ -2,6 +2,7 @@
|
||||
|
||||
namespace App\Http\Controllers\Api;
|
||||
|
||||
use App\Http\Controllers\Api\Concerns\FiltersNumericIds;
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Models\Course;
|
||||
use Dedoc\Scramble\Attributes\ExcludeRouteFromDocs;
|
||||
@@ -16,6 +17,8 @@ use Symfony\Component\HttpFoundation\Response;
|
||||
#[Group(name: 'Kurse', weight: 1)]
|
||||
class CourseController extends Controller
|
||||
{
|
||||
use FiltersNumericIds;
|
||||
|
||||
/**
|
||||
* Kurse auflisten und durchsuchen
|
||||
*
|
||||
@@ -32,7 +35,7 @@ class CourseController extends Controller
|
||||
->select('id', 'name')
|
||||
->orderBy('name')
|
||||
->when($request->has('user_id'),
|
||||
fn (Builder $query) => $query->where('created_by', $request->user_id))
|
||||
fn (Builder $query) => $query->where('created_by', $request->integer('user_id')))
|
||||
->when(
|
||||
$request->search,
|
||||
fn (Builder $query) => $query
|
||||
@@ -40,8 +43,7 @@ class CourseController extends Controller
|
||||
)
|
||||
->when(
|
||||
$request->exists('selected'),
|
||||
fn (Builder $query) => $query->whereIn('id',
|
||||
$request->input('selected', [])),
|
||||
fn (Builder $query) => $query->whereIn('id', $this->numericIds($request)),
|
||||
fn (Builder $query) => $query->limit(10)
|
||||
)
|
||||
->get()
|
||||
|
||||
@@ -2,6 +2,7 @@
|
||||
|
||||
namespace App\Http\Controllers\Api;
|
||||
|
||||
use App\Http\Controllers\Api\Concerns\FiltersNumericIds;
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Http\Requests\Api\StoreLecturerRequest;
|
||||
use App\Http\Requests\Api\UpdateLecturerRequest;
|
||||
@@ -20,6 +21,8 @@ use Symfony\Component\HttpFoundation\Response;
|
||||
#[Group(name: 'Referenten', weight: 4)]
|
||||
class LecturerController extends Controller
|
||||
{
|
||||
use FiltersNumericIds;
|
||||
|
||||
/**
|
||||
* Referenten auflisten und durchsuchen
|
||||
*
|
||||
@@ -32,8 +35,6 @@ class LecturerController extends Controller
|
||||
return Lecturer::query()
|
||||
->select('id', 'name')
|
||||
->orderBy('name')
|
||||
// ->when($request->has('user_id'),
|
||||
// fn(Builder $query) => $query->where('created_by', $request->user_id))
|
||||
->when(
|
||||
$request->search,
|
||||
fn (Builder $query) => $query
|
||||
@@ -41,8 +42,7 @@ class LecturerController extends Controller
|
||||
)
|
||||
->when(
|
||||
$request->exists('selected'),
|
||||
fn (Builder $query) => $query->whereIn('id',
|
||||
$request->input('selected', [])),
|
||||
fn (Builder $query) => $query->whereIn('id', $this->numericIds($request)),
|
||||
fn (Builder $query) => $query->limit(10)
|
||||
)
|
||||
->get()
|
||||
|
||||
@@ -2,6 +2,7 @@
|
||||
|
||||
namespace App\Http\Controllers\Api;
|
||||
|
||||
use App\Http\Controllers\Api\Concerns\FiltersNumericIds;
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Http\Requests\Api\StoreMeetupRequest;
|
||||
use App\Http\Requests\Api\UpdateMeetupRequest;
|
||||
@@ -20,6 +21,8 @@ use Illuminate\Support\Facades\Gate;
|
||||
#[Group(name: 'Meetups', weight: 3)]
|
||||
class MeetupController extends Controller
|
||||
{
|
||||
use FiltersNumericIds;
|
||||
|
||||
#[ExcludeRouteFromDocs]
|
||||
public function ical()
|
||||
{
|
||||
@@ -58,7 +61,7 @@ class MeetupController extends Controller
|
||||
)
|
||||
->when(
|
||||
$request->exists('selected'),
|
||||
fn (Builder $query) => $query->whereIn('id', $request->input('selected', [])),
|
||||
fn (Builder $query) => $query->whereIn('id', $this->numericIds($request)),
|
||||
fn (Builder $query) => $query->limit(10),
|
||||
)
|
||||
->get()
|
||||
|
||||
@@ -8,6 +8,7 @@ use App\Http\Requests\Api\UpdateMeetupEventRequest;
|
||||
use App\Http\Resources\MeetupEventResource;
|
||||
use App\Models\MeetupEvent;
|
||||
use Carbon\Carbon;
|
||||
use Carbon\Exceptions\InvalidFormatException;
|
||||
use Dedoc\Scramble\Attributes\Group;
|
||||
use Dedoc\Scramble\Attributes\PathParameter;
|
||||
use Dedoc\Scramble\Attributes\Response as ResponseAttribute;
|
||||
@@ -30,10 +31,15 @@ class MeetupEventController extends Controller
|
||||
* @return Collection<int, array<string, mixed>>
|
||||
*/
|
||||
#[PathParameter(name: 'date', description: 'Optionales Datum (Y-m-d); filtert auf den Monat dieses Datums.', required: false, type: 'string')]
|
||||
#[ResponseAttribute(status: 400, description: 'Das übergebene Datum ist nicht parsebar (erwartet wird Y-m-d).')]
|
||||
public function __invoke(?string $date = null): Collection
|
||||
{
|
||||
if ($date) {
|
||||
$date = Carbon::parse($date);
|
||||
try {
|
||||
$date = Carbon::parse($date);
|
||||
} catch (InvalidFormatException) {
|
||||
abort(Response::HTTP_BAD_REQUEST, 'Ungültiges Datum. Erwartet wird das Format Y-m-d.');
|
||||
}
|
||||
}
|
||||
$events = MeetupEvent::query()
|
||||
->with([
|
||||
|
||||
@@ -2,6 +2,7 @@
|
||||
|
||||
namespace App\Http\Controllers\Api;
|
||||
|
||||
use App\Http\Controllers\Api\Concerns\FiltersNumericIds;
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Http\Requests\Api\StoreVenueRequest;
|
||||
use App\Http\Requests\Api\UpdateVenueRequest;
|
||||
@@ -20,6 +21,8 @@ use Symfony\Component\HttpFoundation\Response;
|
||||
#[Group(name: 'Stammdaten', weight: 5)]
|
||||
class VenueController extends Controller
|
||||
{
|
||||
use FiltersNumericIds;
|
||||
|
||||
/**
|
||||
* Veranstaltungsorte auflisten und durchsuchen
|
||||
*
|
||||
@@ -42,8 +45,7 @@ class VenueController extends Controller
|
||||
)
|
||||
->when(
|
||||
$request->exists('selected'),
|
||||
fn (Builder $query) => $query->whereIn('id',
|
||||
$request->input('selected', [])),
|
||||
fn (Builder $query) => $query->whereIn('id', $this->numericIds($request)),
|
||||
fn (Builder $query) => $query->limit(10)
|
||||
)
|
||||
->get()
|
||||
|
||||
Reference in New Issue
Block a user