-
Notifications
You must be signed in to change notification settings - Fork 318
Expand file tree
/
Copy pathEnsureFrontendRequestsAreStatefulTest.php
More file actions
91 lines (64 loc) · 2.96 KB
/
EnsureFrontendRequestsAreStatefulTest.php
File metadata and controls
91 lines (64 loc) · 2.96 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
<?php
namespace Laravel\Sanctum\Tests\Feature;
use Illuminate\Http\Request;
use Laravel\Sanctum\Http\Middleware\EnsureFrontendRequestsAreStateful;
use Orchestra\Testbench\Concerns\WithWorkbench;
use Orchestra\Testbench\TestCase;
class EnsureFrontendRequestsAreStatefulTest extends TestCase
{
use WithWorkbench;
protected function defineEnvironment($app)
{
$app['config']->set('sanctum.stateful', ['test.com', '*.test.com']);
}
public function test_request_referer_is_parsed_against_configuration()
{
$request = Request::create('/');
$request->headers->set('referer', 'https://test.com');
$this->assertTrue(EnsureFrontendRequestsAreStateful::fromFrontend($request));
$request = Request::create('/');
$request->headers->set('referer', 'https://wrong.com');
$this->assertFalse(EnsureFrontendRequestsAreStateful::fromFrontend($request));
$request = Request::create('/');
$request->headers->set('referer', 'https://test.com.x');
$this->assertFalse(EnsureFrontendRequestsAreStateful::fromFrontend($request));
$request = Request::create('/');
$request->headers->set('referer', 'https://foobar.test.com/');
$this->assertTrue(EnsureFrontendRequestsAreStateful::fromFrontend($request));
}
public function test_request_origin_fallback()
{
$request = Request::create('/');
$request->headers->set('origin', 'test.com');
$this->assertTrue(EnsureFrontendRequestsAreStateful::fromFrontend($request));
$request = Request::create('/');
$request->headers->set('referer', null);
$request->headers->set('origin', 'test.com');
$this->assertTrue(EnsureFrontendRequestsAreStateful::fromFrontend($request));
$request = Request::create('/');
$request->headers->set('referer', '');
$request->headers->set('origin', 'test.com');
$this->assertTrue(EnsureFrontendRequestsAreStateful::fromFrontend($request));
}
public function test_same_domain_stateful()
{
$request = Request::create('https://app-domain.com/');
$request->headers->set('origin', 'app-domain.com');
config(['sanctum.same_domain_stateful' => false]);
$this->assertFalse(EnsureFrontendRequestsAreStateful::fromFrontend($request));
config(['sanctum.same_domain_stateful' => true]);
$this->assertTrue(EnsureFrontendRequestsAreStateful::fromFrontend($request));
}
public function test_wildcard_matching()
{
$request = Request::create('/');
$request->headers->set('referer', 'https://foo.test.com');
$this->assertTrue(EnsureFrontendRequestsAreStateful::fromFrontend($request));
}
public function test_requests_are_not_stateful_without_referer()
{
$this->app['config']->set('sanctum.stateful', ['']);
$request = Request::create('/');
$this->assertFalse(EnsureFrontendRequestsAreStateful::fromFrontend($request));
}
}