andrewdyer / andrewdyer/command-bus

Middleware validation allows objects without a real execute method

Offen
#4 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
PHP
Sterne
0
Forks
0
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

The `CommandBus::addMiddleware()` uses `is_callable([$middleware, 'execute'])` to validate that middleware has a public `execute()` method. However, `is_callable()` returns `true` for any object implementing `__call()`, even if no concrete `execute()` method exists — contradicting the exception message and documented contract.

Fix: Replace the `is_callable()` check with `method_exists()` + `ReflectionMethod::isPublic():`

```php
isPublic()) {
throw new InvalidArgumentException(...);
}
```

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.