2016-05-19 15:01:28 +01:00
|
|
|
<?php
|
|
|
|
|
|
2024-06-08 19:39:09 +01:00
|
|
|
use App\Http\Middleware\LinkHeadersMiddleware;
|
2024-03-19 20:13:36 +00:00
|
|
|
use Illuminate\Foundation\Application;
|
|
|
|
|
use Illuminate\Foundation\Configuration\Exceptions;
|
|
|
|
|
use Illuminate\Foundation\Configuration\Middleware;
|
2025-10-30 11:49:54 +00:00
|
|
|
use Spatie\LaravelFlare\Facades\Flare;
|
2016-05-19 15:01:28 +01:00
|
|
|
|
2024-03-19 20:13:36 +00:00
|
|
|
return Application::configure(basePath: dirname(__DIR__))
|
|
|
|
|
->withRouting(
|
|
|
|
|
web: __DIR__.'/../routes/web.php',
|
|
|
|
|
commands: __DIR__.'/../routes/console.php',
|
|
|
|
|
health: '/up',
|
|
|
|
|
)
|
|
|
|
|
->withMiddleware(function (Middleware $middleware) {
|
2024-06-08 19:39:09 +01:00
|
|
|
$middleware
|
|
|
|
|
->append(LinkHeadersMiddleware::class)
|
2026-04-07 09:01:19 +01:00
|
|
|
->preventRequestForgery(
|
|
|
|
|
except: [
|
Fix CSRF exemption and array-input crash on revocation/introspection
An Opus code review of the branch caught two real bugs the test suite
structurally couldn't see:
- /revocation and /introspect were never added to bootstrap/app.php's
CSRF except list, so both were fully broken (403) for any real
external client, despite every feature test passing — CSRF
verification is short-circuited entirely while running tests.
Verified live against the running app before and after the fix, and
added a regression test that asserts against the actual configured
exemptions rather than relying on request-time behavior that tests
can't exercise.
- An array-shaped `token` param (e.g. token[]=a&token[]=b) crashed
both endpoints with a 500, since this app promotes PHP warnings
("Array to string conversion") to exceptions. Fixed at the shared
root, MicropubToken::findActive(), which also closes the same latent
hole in VerifyMicropubToken's access_token param that predates this
branch. Verified live and covered with regression tests.
Also applied the review's lower-severity findings: added the missing
introspection_endpoint Link header and metadata test assertions,
removed the now-dead is_string($scopes) array branch in the Micropub
handlers and media controller (scope is unconditionally a string from
the DB now, this guarded against a JWT-array-claim shape that can no
longer occur), dropped a redundant #[Table] model attribute, sized
token_hash to its actual 64-char length, and removed a one-off inline
style in the admin view.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
2026-08-13 17:03:43 +01:00
|
|
|
'auth', // This is the IndieAuth auth endpoint
|
|
|
|
|
'token', // This is the IndieAuth token endpoint
|
|
|
|
|
'revocation', // This is the IndieAuth revocation endpoint
|
|
|
|
|
'introspect', // This is the IndieAuth introspection endpoint
|
2026-04-07 09:01:19 +01:00
|
|
|
'api/post',
|
|
|
|
|
'api/media',
|
|
|
|
|
'micropub/places',
|
|
|
|
|
'webmention',
|
|
|
|
|
],
|
|
|
|
|
originOnly: true
|
|
|
|
|
);
|
2024-03-19 20:13:36 +00:00
|
|
|
})
|
|
|
|
|
->withExceptions(function (Exceptions $exceptions) {
|
2025-10-30 11:49:54 +00:00
|
|
|
Flare::handles($exceptions);
|
2024-03-19 20:13:36 +00:00
|
|
|
})->create();
|