andrewdyer / andrewdyer/command-bus

Middleware validation allows objects without a real execute method

Open
#4 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
PHP
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

The `CommandBus::addMiddleware()` uses `is_callable([$middleware, 'execute'])` to validate that middleware has a public `execute()` method. However, `is_callable()` returns `true` for any object implementing `__call()`, even if no concrete `execute()` method exists — contradicting the exception message and documented contract.

Fix: Replace the `is_callable()` check with `method_exists()` + `ReflectionMethod::isPublic():`

```php
isPublic()) {
throw new InvalidArgumentException(...);
}
```

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.