mirror of
https://github.com/Vateron-Media/XC_VM.git
synced 2026-10-04 12:02:33 +02:00
fix(security): resellers generate activation codes on their own terms only
ActiveCodeService::generateCodes and massAction took several values from the reseller's request that the reseller pages never send: - package_id: any package, not only those the reseller's group sells. - is_trial=1: priced the codes at the package's trial_credits (usually 0) while issuing them as that package's official codes. - max_connections: any connection count. - change_package: any package, with no group check. - enable: also set admin_enabled = 1, lifting an administrator's ban on the code's line. For non-admin callers the package must now be a line package offered to the reseller's group (the list the reseller pages show), the trial price applies only to trial packages, the connection count comes from the package, and enable leaves admin bans alone. Administrators keep every option. Free extension of codes and bouquet choice are offered by the reseller page itself and are left as designed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V2uBUbGApb4A7Rbcoi7dxA
This commit is contained in:
@@ -0,0 +1,27 @@
|
||||
<?php
|
||||
|
||||
use PHPUnit\Framework\TestCase;
|
||||
use XcVm\Domain\Line\ActiveCodeService;
|
||||
|
||||
/**
|
||||
* Resellers generate and re-package activation codes only with packages their
|
||||
* group sells — the same list the reseller page offers. The service took any
|
||||
* package id from the request.
|
||||
*/
|
||||
final class ActiveCodePackageRuleTest extends TestCase {
|
||||
|
||||
private function allowed(array $rPackage, array $rUser): bool {
|
||||
$rMethod = new ReflectionMethod(ActiveCodeService::class, 'packageAvailableTo');
|
||||
$rMethod->setAccessible(true);
|
||||
return $rMethod->invoke(null, $rPackage, $rUser);
|
||||
}
|
||||
|
||||
public function testOnlyLinePackagesOfTheResellersGroup(): void {
|
||||
$rReseller = ['id' => 7, 'member_group_id' => 2];
|
||||
$this->assertTrue($this->allowed(['is_line' => 1, 'groups' => '[2,3]'], $rReseller));
|
||||
$this->assertTrue($this->allowed(['is_line' => '1', 'groups' => '["2"]'], $rReseller));
|
||||
$this->assertFalse($this->allowed(['is_line' => 1, 'groups' => '[3]'], $rReseller), 'another group');
|
||||
$this->assertFalse($this->allowed(['is_line' => 0, 'groups' => '[2]'], $rReseller), 'not a line package');
|
||||
$this->assertFalse($this->allowed(['is_line' => 1, 'groups' => ''], $rReseller), 'no groups');
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user