create();
$otherUser = User::factory()->create();
$endpoint = WebhookEndpoint::factory()->ownedBy($owner)->create();
$this->get(route('inspect.show', ['token' => $endpoint->token]))->assertForbidden();
$this->actingAs($otherUser)->get(route('inspect.show', ['token' => $endpoint->token]))->assertForbidden();
$this->actingAs($owner)->get(route('inspect.show', ['token' => $endpoint->token]))->assertOk();
}
public function test_private_endpoints_can_only_be_deleted_by_the_owner(): void
{
$owner = User::factory()->create();
$otherUser = User::factory()->create();
$endpoint = WebhookEndpoint::factory()->ownedBy($owner)->create();
$this->actingAs($otherUser)
->delete(route('inspect.destroy', ['token' => $endpoint->token]))
->assertForbidden();
$this->assertModelExists($endpoint);
$this->actingAs($owner)
->delete(route('inspect.destroy', ['token' => $endpoint->token]))
->assertRedirect(route('home'));
$this->assertModelMissing($endpoint);
}
public function test_livewire_inspector_can_filter_search_select_and_delete_requests(): void
{
$endpoint = WebhookEndpoint::factory()->create();
$getRequest = WebhookRequest::factory()->forEndpoint($endpoint)->create([
'method' => 'GET',
'request_uri' => '/hook/test?search=visible',
'body' => '',
'body_size' => 25,
]);
WebhookRequest::factory()->forEndpoint($endpoint)->create([
'method' => 'POST',
'request_uri' => '/hook/other',
]);
Livewire::test(Inspector::class, ['endpoint' => $endpoint])
->assertSee('/hook/test?search=visible')
->set('methodFilter', 'POST')
->assertSee('/hook/other')
->assertDontSee('/hook/test?search=visible')
->set('methodFilter', 'ALL')
->set('search', 'visible')
->assertSee('/hook/test?search=visible')
->assertDontSee('/hook/other')
->call('selectRequest', $getRequest->getKey())
->assertSee('<script>alert(1)</script>', false)
->assertDontSee('', false)
->call('deleteRequest', $getRequest->getKey());
$this->assertModelMissing($getRequest);
}
public function test_private_endpoints_can_be_created_from_the_dashboard(): void
{
$user = User::factory()->create();
Livewire::actingAs($user)
->test(Dashboard::class)
->set('endpointName', 'Payments')
->call('saveEndpoint')
->assertRedirect();
$endpoint = $user->webhookEndpoints()->firstOrFail();
$this->assertFalse($endpoint->is_public);
$this->assertSame('Payments', $endpoint->name);
$this->assertNull($endpoint->expires_at);
}
public function test_private_endpoint_response_can_be_configured_from_the_inspector(): void
{
$user = User::factory()->create();
$endpoint = WebhookEndpoint::factory()->ownedBy($user)->create();
Livewire::actingAs($user)
->test(Inspector::class, ['endpoint' => $endpoint])
->set('responseStatus', 202)
->set('responseHeadersJson', '{"Content-Type":"text/plain","X-Inspector":"accepted"}')
->set('responseBody', 'queued')
->call('saveResponse')
->assertSet('responseSaved', true);
$endpoint->refresh();
$this->assertSame(202, $endpoint->response_status);
$this->assertSame(
['Content-Type' => 'text/plain', 'X-Inspector' => 'accepted'],
$endpoint->response_headers,
);
$this->assertSame('queued', $endpoint->response_body);
}
public function test_request_body_is_escaped_in_the_inspector(): void
{
$endpoint = WebhookEndpoint::factory()->create();
$webhookRequest = WebhookRequest::factory()->forEndpoint($endpoint)->create([
'body' => '
',
'body_size' => 29,
]);
Livewire::test(Inspector::class, ['endpoint' => $endpoint])
->call('selectRequest', $webhookRequest->getKey())
->assertDontSee('
', false)
->assertSee('<img src=x onerror=alert(1)>', false);
}
}