assertNoExternalUrls($this->get(route('login'))->assertOk()->getContent()); } public function test_authenticated_pages_only_reference_the_application_host(): void { $this->actingAs(User::factory()->create()) ->withSession(['auth.password_confirmed_at' => time()]); foreach (['dashboard', 'profile.edit', 'security.edit', 'appearance.edit'] as $route) { $this->assertNoExternalUrls($this->get(route($route))->assertOk()->getContent(), $route); } } private function assertNoExternalUrls(string $html, string $page = 'login'): void { preg_match_all('/(?:src|href|action)=["\'](https?:\/\/[^"\']+)/i', $html, $matches); $external = array_values(array_filter( $matches[1], fn (string $url) => ! str_starts_with($url, config('app.url')), )); $this->assertSame([], $external, "Externe URLs auf Seite {$page}"); } }