fix(spec113): enforce 10/min system login throttle
This commit is contained in:
parent
8ef221b48e
commit
4f1568b759
@ -14,6 +14,14 @@
|
||||
|
||||
class Login extends BaseLogin
|
||||
{
|
||||
/**
|
||||
* Filament's base login page uses Livewire-level rate limiting. We override it
|
||||
* to enforce the System panel policy via Laravel's RateLimiter (SR-003).
|
||||
*/
|
||||
protected function rateLimit($maxAttempts, $decaySeconds = 60, $method = null, $component = null): void
|
||||
{
|
||||
}
|
||||
|
||||
public function authenticate(): ?LoginResponse
|
||||
{
|
||||
$data = $this->form->getState();
|
||||
|
||||
@ -30,6 +30,9 @@
|
||||
]);
|
||||
|
||||
for ($i = 0; $i < 10; $i++) {
|
||||
Filament::setCurrentPanel('system');
|
||||
Filament::bootCurrentPanel();
|
||||
|
||||
Livewire::test(Login::class)
|
||||
->set('data.email', $user->email)
|
||||
->set('data.password', 'wrong-password')
|
||||
@ -37,6 +40,9 @@
|
||||
->assertHasErrors(['data.email']);
|
||||
}
|
||||
|
||||
Filament::setCurrentPanel('system');
|
||||
Filament::bootCurrentPanel();
|
||||
|
||||
Livewire::test(Login::class)
|
||||
->set('data.email', $user->email)
|
||||
->set('data.password', 'wrong-password')
|
||||
@ -59,4 +65,3 @@
|
||||
expect($latestAudit)->not->toBeNull();
|
||||
expect($latestAudit->metadata['reason'] ?? null)->toBe('throttled');
|
||||
});
|
||||
|
||||
|
||||
Loading…
Reference in New Issue
Block a user