andrewdyer / andrewdyer/command-bus

Middleware validation allows objects without a real execute method

オープン
#4 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
PHP
スター
0
フォーク
0
PR マージ指標
30日以内にマージされた PR はありません

説明

The `CommandBus::addMiddleware()` uses `is_callable([$middleware, 'execute'])` to validate that middleware has a public `execute()` method. However, `is_callable()` returns `true` for any object implementing `__call()`, even if no concrete `execute()` method exists — contradicting the exception message and documented contract.

Fix: Replace the `is_callable()` check with `method_exists()` + `ReflectionMethod::isPublic():`

```php
isPublic()) {
throw new InvalidArgumentException(...);
}
```

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。