<?php

/**
 * Penetration Testing Checklist — KiyoHR
 */

return [
    'authentication' => [
        'Brute force login (web + API) — expect throttle',
        'Password reset token reuse / enumeration',
        '2FA bypass via API when company policy requires enrollment',
        'Session fixation after login (CSRF + regenerate)',
        'Remember-me cookie Secure/HttpOnly flags on HTTPS',
    ],
    'authorization' => [
        'Employee API create/update/delete as plain employee role',
        'Cross-tenant company_id IDOR on employees, leaves, documents',
        'Leave approve as non-manager',
        'SuperAdmin routes as tenant admin',
        'Gate policy bypass for role name admin (should no longer auto-allow)',
    ],
    'payroll' => [
        'Bank export without payrolls_view',
        'Payslip download for other employee',
        'Cycle unlock without permission',
    ],
    'attendance' => [
        'Face attendance without token',
        'Face attendance for another user while authenticated',
        'ZKTeco webhook with wrong Basic auth / IP allowlist',
        'Attendance show for peer outside visibleStaffUserIds',
    ],
    'leave' => [
        'Update/delete another user pending leave via API',
        'Attachment MIME bypass (php/exe)',
    ],
    'recruitment' => [
        'Resume path guessing under /storage after private migration',
        'Applicant resume download cross-company',
    ],
    'employee_profile' => [
        'Mass-assign is_superadmin / company_id via profile or API',
        'Export PII without auth',
    ],
    'reports' => [
        'Audit export without manage_settings',
        'Form submission export IDOR',
    ],
    'api' => [
        'CORS with arbitrary Origin header',
        'Rate limit exhaustion on /api/*',
        'Token replay after logout / password reset',
    ],
    'mobile_app' => [
        'Expired Sanctum token',
        'Face sync returns raw face_data (should not)',
    ],
    'admin_portal' => [
        'Company plan change without superadmin',
        'Razorpay webhook signature forgery',
        'Payment settings JSON web exposure',
    ],
];
