Files
Gnuboard7/tests/scenarios/storage-serve-route-disabled.yaml
2026-07-01 10:30:32 +09:00

41 lines
1.9 KiB
YAML

# audit:allow test-scenario-coverage reason: 본 매니페스트는 /storage 자동 서빙 라우트 비노출 시나리오 SSoT. 핵심 회귀 가드는 test_files 의 통과 테스트로 커버.
feature: /storage/{path} 자동 서빙 라우트 비노출 (공개#52)
description: |
local/modules/plugins 디스크의 serve => false 로 Laravel 이 자동 생성하던
GET/PUT /storage/{path} 라우트를 미등록 상태로 전환하는 시나리오.
배경:
- serve => true 디스크마다 Laravel 12 가 GET(다운로드)/PUT(업로드) /storage/{path}
라우트를 자동 등록. PUT 은 인증·권한·MIME·용량 검사 없이 임의 경로 파일 쓰기 입구.
- 이 서명 URL 을 생성·사용하는 G7 코드가 0줄(의존성 0 재확인 완료) → 불필요한 위험 표면.
- 실제 업로드는 /api/.../attachments + StorageInterface(attachments serve=false),
확장 에셋은 public/build, ckeditor5 는 자체 ImageServeController 경유.
axes:
disk: [local, modules, plugins, attachments, settings, public]
http_method: [GET, PUT]
route_state: [before_fix_serve_true, after_fix_serve_false]
exclusions:
- { disk: attachments, reason: "이미 serve=false (변경 대상 아님)" }
- { disk: settings, reason: "이미 serve=false (변경 대상 아님)" }
- { disk: public, reason: "serve 미설정 + visibility public, 심볼릭 링크 URL 사용 (자동 라우트 무관)" }
effects:
- storage_local_serve_route_unregistered
- storage_modules_serve_route_unregistered
- storage_plugins_serve_route_unregistered
- storage_put_upload_entry_not_handled
- attachment_upload_download_unaffected
- extension_asset_serving_unaffected
- disk_storage_facade_put_get_still_works
test_files:
- tests/Feature/StorageServeRouteTest.php
rules_layer_coverage:
- rule: no-storage-disk-direct
coverage: 변경은 config 한정 — Storage facade 직접 호출 도입 없음