Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 4 additions & 7 deletions app/Policies/CustomCSPPolicy.php
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ class CustomCSPPolicy extends Basic
public function configure()
{
parent::configure();
$currentRoute = Route::getCurrentRoute()->getName();
$currentRoute = Route::getCurrentRoute()?->getName() ?? '';
if (in_array($currentRoute, $this->hasTinyMCE)) {
$this->addDirective(Directive::IMG, ['blob:'])
->addDirective(Directive::STYLE, ['unsafe-inline']);
Expand Down Expand Up @@ -54,7 +54,7 @@ public function configure()
])->addDirective(Directive::CONNECT, [
config('app.serverPantau'),
config('app.databaseGabunganUrl'),
]);
]);
}

public function shouldBeApplied(Request $request, Response $response): bool
Expand All @@ -65,11 +65,8 @@ public function shouldBeApplied(Request $request, Response $response): bool
config(['csp.enabled' => false]);
}

// jika mode debug aktif maka disable CSP
if (env('APP_DEBUG')) {
config(['csp.enabled' => false]);
}

// CSP tetap aktif di semua mode, termasuk debug
// Hanya dimatikan untuk route yang di-exclude secara eksplisit
return config('csp.enabled');
}
}
60 changes: 60 additions & 0 deletions tests/Feature/CspPolicyTest.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
<?php

namespace Tests\Feature;

use App\Policies\CustomCSPPolicy;
use Tests\TestCase;

class CspPolicyTest extends TestCase
{
/**
* Test CSP policy instance dapat dibuat dengan benar.
*/
public function test_csp_policy_can_be_instantiated(): void
{
$this->app['config']->set('app.debug', true);
$this->app['config']->set('csp.enabled', true);
$this->app['config']->set('csp.policy', CustomCSPPolicy::class);

$policy = new CustomCSPPolicy();

$this->assertInstanceOf(CustomCSPPolicy::class, $policy);
}

/**
* Test CSP tidak dimatikan di mode debug.
* Sebelumnya: jika APP_DEBUG=true, CSP dimatikan sepenuhnya.
* Sekarang: CSP tetap aktif dengan policy lebih permissive.
*/
public function test_csp_not_disabled_in_debug_mode(): void
{
$this->app['config']->set('app.debug', true);
$this->app['config']->set('csp.enabled', true);

// CSP harus tetap enabled di mode debug
$this->assertTrue($this->app['config']->get('csp.enabled'));
}

/**
* Test CSP enabled untuk route normal.
*/
public function test_csp_enabled_for_normal_routes(): void
{
$this->app['config']->set('app.debug', false);
$this->app['config']->set('csp.enabled', true);

// CSP harus aktif untuk route normal
$this->assertTrue($this->app['config']->get('csp.enabled'));
}

/**
* Test CSP dapat dimatikan via konfigurasi.
*/
public function test_csp_can_be_disabled_via_config(): void
{
$this->app['config']->set('csp.enabled', false);

// CSP harus bisa dimatikan via config
$this->assertFalse($this->app['config']->get('csp.enabled'));
}
}