Files
einundzwanzig-app/tests/Feature/Api/ApiIndexInputHardeningTest.php
T
HolgerHatGarKeineNode 3cad5f5636 **Enhance input validation and error handling across APIs**
- 🛠️ Refactored controllers to utilize `FiltersNumericIds` concern, ensuring secure numeric ID filtering and avoiding type-sensitive errors in queries.
-  Added feature tests to validate robust input hardening for non-numeric or malformed query parameters (`user_id`, `selected[]`).
- 🔒 Introduced `PublicPropertyNotFoundException` handling in Livewire, returning 400 for invalid property probes and suppressing unnecessary log entries.
-  Updated `MeetupEventController` to handle invalid date formats gracefully, aborting with a 400 response instead of 500.
-  Expanded exception handling pipeline for enhanced resilience against malformed input, bot noise, and exploitable probes.
2026-06-08 02:53:44 +02:00

30 lines
868 B
PHP

<?php
use App\Models\Course;
use App\Models\Venue;
it('drops non-numeric selected values on GET /api/courses instead of erroring', function () {
$course = Course::factory()->create();
$response = $this->getJson('/api/courses?selected[]='.$course->id.'&selected[]=foo');
$response->assertSuccessful();
expect(collect($response->json())->pluck('id')->all())->toBe([$course->id]);
});
it('casts a non-numeric user_id to an empty filter on GET /api/courses', function () {
Course::factory()->create();
$this->getJson('/api/courses?user_id=abc')
->assertSuccessful()
->assertJsonCount(0);
});
it('tolerates a non-array selected value on GET /api/venues without a 500', function () {
Venue::factory()->create();
$this->getJson('/api/venues?selected=foo')
->assertSuccessful()
->assertJsonCount(0);
});