Skip to content

[13.x] Fake the pwnedpasswords API in ValidationPasswordRuleTest - #60927

Merged
taylorotwell merged 1 commit into
laravel:13.xfrom
lucasmichot:fix/uncompromised-password-test-network-call
Jul 30, 2026
Merged

[13.x] Fake the pwnedpasswords API in ValidationPasswordRuleTest#60927
taylorotwell merged 1 commit into
laravel:13.xfrom
lucasmichot:fix/uncompromised-password-test-network-call

Conversation

@lucasmichot

@lucasmichot lucasmichot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

This test made a real network call to https://api.pwnedpasswords.com. On the GitHub Actions Windows runners this call sometimes fails, and the error handling itself fails too (no ExceptionHandler bound in this test), so the real network error gets hidden and the test just fails:

This fixes it by faking the HTTP response instead of calling the real API. ValidationNotPwnedVerifierTest already does this with mocks, so this test was the only one still using the network.

This is not new: the test has always called the real API, since it was added in #36960. It only fails sometimes, when the network call is unreliable.

@github-actions

Copy link
Copy Markdown

Thanks for submitting a PR!

Note that draft PRs are not reviewed. If you would like a review, please mark your pull request as ready for review in the GitHub user interface.

Pull requests that are abandoned in draft may be closed due to inactivity.

@lucasmichot
lucasmichot force-pushed the fix/uncompromised-password-test-network-call branch from aabf67b to 5923e6d Compare July 29, 2026 17:20
…romised

This test made a real network call to https://api.pwnedpasswords.com
through NotPwnedVerifier, since it doesn't boot a full application
container. On the GitHub Actions Windows runners this call sometimes
fails, and since report() itself needs a bound ExceptionHandler, the
catch block in NotPwnedVerifier::search() throws its own
BindingResolutionException instead, masking the network error and
failing the test intermittently.

Binds Illuminate\Http\Client\Factory as a singleton in setUp() so
Http::fake() controls the same instance the validator resolves, and
fakes deterministic pwnedpasswords-style responses for the known
passwords the test asserts against.
@lucasmichot
lucasmichot force-pushed the fix/uncompromised-password-test-network-call branch from 5923e6d to 0030ae7 Compare July 29, 2026 17:21
@lucasmichot lucasmichot changed the title Fake the pwnedpasswords API in ValidationPasswordRuleTest [13.x] Fake the pwnedpasswords API in ValidationPasswordRuleTest Jul 29, 2026
@lucasmichot
lucasmichot marked this pull request as ready for review July 29, 2026 17:22
@taylorotwell
taylorotwell merged commit 4c63152 into laravel:13.x Jul 30, 2026
53 checks passed
@lucasmichot
lucasmichot deleted the fix/uncompromised-password-test-network-call branch August 3, 2026 18:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants