- TallStackUI 4 (MIT) statt Flux; Komponenten mit Präfix ts- (<x-ts-…>) - Layouts, Login-, Passwort-, 2FA- und Einstellungsseiten neu aufgebaut - Livewire-Skripte explizit in beiden Layouts, damit Alpine auch auf den Fortify-Seiten ohne Livewire-Komponente läuft - Dark Mode über tallstackui_darkTheme(), ohne Aufblitzen beim Laden - Registrierungs-View und ungenutzte Layout-Varianten entfernt - Test: Seiten laden keine Ressourcen von fremden Hosts (Vorgabe "alles lokal") Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
44 lines
1.4 KiB
PHP
44 lines
1.4 KiB
PHP
<?php
|
|
|
|
namespace Tests\Feature;
|
|
|
|
use App\Models\User;
|
|
use Illuminate\Foundation\Testing\RefreshDatabase;
|
|
use Tests\TestCase;
|
|
|
|
/**
|
|
* Vorgabe "alles lokal": Seiten dürfen keine Ressourcen von fremden Hosts laden
|
|
* (z. B. ui-avatars.com oder gravatar.com über ts-avatar, Web-Fonts von CDNs).
|
|
*/
|
|
class NoExternalResourcesTest extends TestCase
|
|
{
|
|
use RefreshDatabase;
|
|
|
|
public function test_guest_pages_only_reference_the_application_host(): void
|
|
{
|
|
$this->assertNoExternalUrls($this->get(route('login'))->assertOk()->getContent());
|
|
}
|
|
|
|
public function test_authenticated_pages_only_reference_the_application_host(): void
|
|
{
|
|
$this->actingAs(User::factory()->create())
|
|
->withSession(['auth.password_confirmed_at' => time()]);
|
|
|
|
foreach (['dashboard', 'profile.edit', 'security.edit', 'appearance.edit'] as $route) {
|
|
$this->assertNoExternalUrls($this->get(route($route))->assertOk()->getContent(), $route);
|
|
}
|
|
}
|
|
|
|
private function assertNoExternalUrls(string $html, string $page = 'login'): void
|
|
{
|
|
preg_match_all('/(?:src|href|action)=["\'](https?:\/\/[^"\']+)/i', $html, $matches);
|
|
|
|
$external = array_values(array_filter(
|
|
$matches[1],
|
|
fn (string $url) => ! str_starts_with($url, config('app.url')),
|
|
));
|
|
|
|
$this->assertSame([], $external, "Externe URLs auf Seite {$page}");
|
|
}
|
|
}
|