Skip to content

Test that the unblock token only passes the unblock view - #235

Open
codeling wants to merge 1 commit into
mainfrom
claude/amazing-carson-arhrpg
Open

codeling wants to merge 1 commit into
mainfrom
claude/amazing-carson-arhrpg

Conversation

@codeling

@codeling codeling commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Summary

Adds two integration tests to BlockedRequestTest for the unblock-token exemption:

  • testUnblockTokenPassIsLimitedToTheUnblockView: with a valid token, requests with another task or component (including task=user.LOGIN, option=com_login), upper-case option/view, or an array-valued token stay blocked; only option=com_bfstop&view=tokenunblock passes.
  • testUnblockTokenOfAnotherAddressIsNoPassForTheUnblockView: a valid token of another address's block doesn't open the unblock view.

The expected outcomes were observed with tests/Integration/fixtures/request.php against Joomla 5.4.8 on PostgreSQL. The new tests are syntax-checked but were not run under PHPUnit (not available in the session).

No production code is changed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01LhhhdjhErC9ZiaS4HyRjsh


Generated by Claude Code

A valid token must open the unblock view and nothing else: other tasks or
components (also in other spellings) and non-string tokens stay blocked, and
the token of another address's block is no pass.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LhhhdjhErC9ZiaS4HyRjsh
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants