andrewdyer / andrewdyer/command-bus

Middleware validation allows objects without a real execute method

未关闭
#4 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
PHP
星标
0
派生
0
PR 合并指标
30 天内没有已合并 PR

描述

The `CommandBus::addMiddleware()` uses `is_callable([$middleware, 'execute'])` to validate that middleware has a public `execute()` method. However, `is_callable()` returns `true` for any object implementing `__call()`, even if no concrete `execute()` method exists — contradicting the exception message and documented contract.

Fix: Replace the `is_callable()` check with `method_exists()` + `ReflectionMethod::isPublic():`

```php
isPublic()) {
throw new InvalidArgumentException(...);
}
```

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。