Files
einundzwanzig-app/tests/Feature/LivewireExploitProbeTest.php
T
HolgerHatGarKeineNode 3a8775fa52 🛡️ **Add robust Livewire payload validation and throttling**
-  Implemented handling for `CorruptComponentPayloadException` to prevent logging noise and improve exception management.
- 🛠️ Added IP-based throttling (120 requests/min) for the `/livewire/update` endpoint with middleware integration for better traffic control.
-  Introduced unit tests to validate throttle settings and middleware application.
- 🧪 Enhanced tests for ensuring silent handling of corrupt payload scenarios and reduced log noise.
2026-06-04 11:45:02 +02:00

60 lines
2.0 KiB
PHP

<?php
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Facades\Route;
use Livewire\Exceptions\MethodNotFoundException;
use Livewire\Features\SupportLifecycleHooks\DirectlyCallingLifecycleHooksNotAllowedException;
use Livewire\Mechanisms\HandleComponents\CorruptComponentPayloadException;
it('returns 400 for lifecycle-hook probing instead of 500', function () {
Route::get('/_test/livewire-lifecycle-probe', function () {
throw new DirectlyCallingLifecycleHooksNotAllowedException('dehydrate', 'auth.login');
});
expect($this->get('/_test/livewire-lifecycle-probe')->status())->toBe(400);
});
it('returns 400 for magic-method probing instead of 500', function () {
Route::get('/_test/livewire-magic-method-probe', function () {
throw new MethodNotFoundException('__call');
});
expect($this->get('/_test/livewire-magic-method-probe')->status())->toBe(400);
});
it('does not report Livewire exploit probes to the logs', function () {
Log::spy();
Route::get('/_test/livewire-probe-log', function () {
throw new DirectlyCallingLifecycleHooksNotAllowedException('dehydrate', 'auth.login');
});
$this->get('/_test/livewire-probe-log')->assertStatus(400);
Log::shouldNotHaveReceived('error');
Log::shouldNotHaveReceived('critical');
Log::shouldNotHaveReceived('emergency');
});
it('still surfaces genuine method-not-found bugs', function () {
Route::get('/_test/livewire-real-method-not-found', function () {
throw new MethodNotFoundException('saveProfile');
});
expect($this->get('/_test/livewire-real-method-not-found')->status())->not->toBe(400);
});
it('does not report corrupt Livewire snapshot payloads', function () {
Log::spy();
Route::get('/_test/livewire-corrupt-payload', function () {
throw new CorruptComponentPayloadException;
});
$this->get('/_test/livewire-corrupt-payload');
Log::shouldNotHaveReceived('error');
Log::shouldNotHaveReceived('critical');
Log::shouldNotHaveReceived('emergency');
});