-
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
complexity:mediumLess than 1 dayLess than 1 daylang:phpPHP/LaravelPHP/Laravelpriority:mediumNormal queueNormal queuetype:featureNew feature or enhancementNew feature or enhancement
Description
Finding
No dedicated security test suite exists to verify input sanitisation, authentication, authorisation, and CSRF protections.
Fix
Create a security-focused test suite covering OWASP Top 10 scenarios relevant to the framework.
Acceptance Criteria
- XSS injection tests for input sanitisation
- SQL injection tests for query building
- CSRF protection verification
- Authentication bypass attempt tests
- Authorisation boundary tests (tenant isolation)
- SSRF prevention tests
- Tests use Pest syntax and are in a dedicated Tests/Security/ directory
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
complexity:mediumLess than 1 dayLess than 1 daylang:phpPHP/LaravelPHP/Laravelpriority:mediumNormal queueNormal queuetype:featureNew feature or enhancementNew feature or enhancement