Phase 6: security & ops hardening (T6.1-T6.5)
- T6.1: named rate limiters (api-read/api-write/api-auth/api-webhooks), applied per module route group with tighter limits on booking/payment writes and the KBZ webhook than read-only catalog/routing endpoints. - T6.2: install spatie/laravel-activitylog; LogsActivity on Booking/ Payment/Refund status transitions and catalog/pricing admin CRUD (EvCompany, Destination, DepartureTimeSlot, EvRoute, RoutePricing). New IdentityPlugin with a read-only AuditLogResource gated by view_audit_log. - T6.3: JSON error envelope for api/* in bootstrap/app.php (401/403/404/ 405/429/500 fallback), plus PaymentGatewayException (422 declined / 502 unavailable). - T6.4: feature tests proving the FastAPI agent token gets 403 on refund/cancel-not-owned and 405 (no write handler) on catalog/routing writes. - T6.5: install gboquizosanchez/filament-log-viewer with a custom Filament admin theme (required for its views' Tailwind classes to compile), LOG_CHANNEL/FILAMENT_LOG_VIEWER_DRIVER=daily, registered under Operations in the sidebar. 252 tests passing.
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
<?php
|
||||
|
||||
use App\Models\User;
|
||||
|
||||
/**
|
||||
* T6.1 — write-heavy booking/payment endpoints are throttled tighter than
|
||||
* read-only catalog/routing endpoints (domain.md §8).
|
||||
*/
|
||||
test('the booking write limiter is tighter than the catalog read limiter', function () {
|
||||
$user = User::factory()->create();
|
||||
$token = $user->createToken('test')->plainTextToken;
|
||||
|
||||
$readResponses = collect(range(1, 25))->map(
|
||||
fn () => $this->withHeader('Authorization', "Bearer {$token}")->getJson('/api/v1/companies')
|
||||
);
|
||||
expect($readResponses->every(fn ($response) => $response->status() !== 429))->toBeTrue();
|
||||
|
||||
$writeResponses = collect(range(1, 25))->map(
|
||||
fn () => $this->withHeader('Authorization', "Bearer {$token}")->postJson('/api/v1/bookings', [])
|
||||
);
|
||||
expect($writeResponses->contains(fn ($response) => $response->status() === 429))->toBeTrue();
|
||||
});
|
||||
|
||||
test('a rate-limited api request gets a 429 JSON envelope', function () {
|
||||
$user = User::factory()->create();
|
||||
$token = $user->createToken('test')->plainTextToken;
|
||||
|
||||
$responses = collect(range(1, 25))->map(
|
||||
fn () => $this->withHeader('Authorization', "Bearer {$token}")->postJson('/api/v1/bookings', [])
|
||||
);
|
||||
|
||||
$limited = $responses->first(fn ($response) => $response->status() === 429);
|
||||
|
||||
expect($limited)->not->toBeNull();
|
||||
$limited->assertJsonStructure(['message']);
|
||||
});
|
||||
Reference in New Issue
Block a user