jonnybarnes.uk/resources/views/admin/tokens/index.blade.php

27 lines
903 B
PHP
Raw Normal View History

@extends('master')
@section('title')List Tokens « Admin CP « @stop
@section('content')
<h1>Micropub Tokens</h1>
@if($tokens->isEmpty())
<p>No tokens have been issued.</p>
@else
<ul>
@foreach($tokens as $token)
<li>
{{ $token->client_id }} scope: {{ $token->scope }} issued {{ $token->created_at->diffForHumans() }}
@if($token->isRevoked)
revoked {{ $token->revoked_at->diffForHumans() }}
@else
Fix CSRF exemption and array-input crash on revocation/introspection An Opus code review of the branch caught two real bugs the test suite structurally couldn't see: - /revocation and /introspect were never added to bootstrap/app.php's CSRF except list, so both were fully broken (403) for any real external client, despite every feature test passing — CSRF verification is short-circuited entirely while running tests. Verified live against the running app before and after the fix, and added a regression test that asserts against the actual configured exemptions rather than relying on request-time behavior that tests can't exercise. - An array-shaped `token` param (e.g. token[]=a&token[]=b) crashed both endpoints with a 500, since this app promotes PHP warnings ("Array to string conversion") to exceptions. Fixed at the shared root, MicropubToken::findActive(), which also closes the same latent hole in VerifyMicropubToken's access_token param that predates this branch. Verified live and covered with regression tests. Also applied the review's lower-severity findings: added the missing introspection_endpoint Link header and metadata test assertions, removed the now-dead is_string($scopes) array branch in the Micropub handlers and media controller (scope is unconditionally a string from the DB now, this guarded against a JWT-array-claim shape that can no longer occur), dropped a redundant #[Table] model attribute, sized token_hash to its actual 64-char length, and removed a one-off inline style in the admin view. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
2026-08-13 17:03:43 +01:00
<form action="/admin/tokens/{{ $token->id }}/revoke" method="post">
{{ csrf_field() }}
{{ method_field('PUT') }}
<button type="submit" name="revoke">Revoke</button>
</form>
@endif
</li>
@endforeach
</ul>
@endif
@stop