jonnybarnes.uk/app/Models/MicropubToken.php

50 lines
1.3 KiB
PHP
Raw Permalink Normal View History

<?php
declare(strict_types=1);
namespace App\Models;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Casts\Attribute;
use Illuminate\Database\Eloquent\Model;
#[Fillable(['token_hash', 'client_id', 'me', 'scope'])]
class MicropubToken extends Model
{
protected function casts(): array
{
return [
'revoked_at' => 'datetime',
];
}
public function revoke(): void
{
$this->forceFill(['revoked_at' => now()])->save();
}
/**
Fix CSRF exemption and array-input crash on revocation/introspection An Opus code review of the branch caught two real bugs the test suite structurally couldn't see: - /revocation and /introspect were never added to bootstrap/app.php's CSRF except list, so both were fully broken (403) for any real external client, despite every feature test passing — CSRF verification is short-circuited entirely while running tests. Verified live against the running app before and after the fix, and added a regression test that asserts against the actual configured exemptions rather than relying on request-time behavior that tests can't exercise. - An array-shaped `token` param (e.g. token[]=a&token[]=b) crashed both endpoints with a 500, since this app promotes PHP warnings ("Array to string conversion") to exceptions. Fixed at the shared root, MicropubToken::findActive(), which also closes the same latent hole in VerifyMicropubToken's access_token param that predates this branch. Verified live and covered with regression tests. Also applied the review's lower-severity findings: added the missing introspection_endpoint Link header and metadata test assertions, removed the now-dead is_string($scopes) array branch in the Micropub handlers and media controller (scope is unconditionally a string from the DB now, this guarded against a JWT-array-claim shape that can no longer occur), dropped a redundant #[Table] model attribute, sized token_hash to its actual 64-char length, and removed a one-off inline style in the admin view. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
2026-08-13 17:03:43 +01:00
* Find the active (non-revoked) token matching a raw bearer token value.
*
* Accepts mixed because callers pass request input directly, which PHP
* lets be an array (e.g. a client sending token[]=a) - casting that to
* string would throw, so anything non-string is just treated as absent.
*/
Fix CSRF exemption and array-input crash on revocation/introspection An Opus code review of the branch caught two real bugs the test suite structurally couldn't see: - /revocation and /introspect were never added to bootstrap/app.php's CSRF except list, so both were fully broken (403) for any real external client, despite every feature test passing — CSRF verification is short-circuited entirely while running tests. Verified live against the running app before and after the fix, and added a regression test that asserts against the actual configured exemptions rather than relying on request-time behavior that tests can't exercise. - An array-shaped `token` param (e.g. token[]=a&token[]=b) crashed both endpoints with a 500, since this app promotes PHP warnings ("Array to string conversion") to exceptions. Fixed at the shared root, MicropubToken::findActive(), which also closes the same latent hole in VerifyMicropubToken's access_token param that predates this branch. Verified live and covered with regression tests. Also applied the review's lower-severity findings: added the missing introspection_endpoint Link header and metadata test assertions, removed the now-dead is_string($scopes) array branch in the Micropub handlers and media controller (scope is unconditionally a string from the DB now, this guarded against a JWT-array-claim shape that can no longer occur), dropped a redundant #[Table] model attribute, sized token_hash to its actual 64-char length, and removed a one-off inline style in the admin view. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
2026-08-13 17:03:43 +01:00
public static function findActive(mixed $rawToken): ?self
{
Fix CSRF exemption and array-input crash on revocation/introspection An Opus code review of the branch caught two real bugs the test suite structurally couldn't see: - /revocation and /introspect were never added to bootstrap/app.php's CSRF except list, so both were fully broken (403) for any real external client, despite every feature test passing — CSRF verification is short-circuited entirely while running tests. Verified live against the running app before and after the fix, and added a regression test that asserts against the actual configured exemptions rather than relying on request-time behavior that tests can't exercise. - An array-shaped `token` param (e.g. token[]=a&token[]=b) crashed both endpoints with a 500, since this app promotes PHP warnings ("Array to string conversion") to exceptions. Fixed at the shared root, MicropubToken::findActive(), which also closes the same latent hole in VerifyMicropubToken's access_token param that predates this branch. Verified live and covered with regression tests. Also applied the review's lower-severity findings: added the missing introspection_endpoint Link header and metadata test assertions, removed the now-dead is_string($scopes) array branch in the Micropub handlers and media controller (scope is unconditionally a string from the DB now, this guarded against a JWT-array-claim shape that can no longer occur), dropped a redundant #[Table] model attribute, sized token_hash to its actual 64-char length, and removed a one-off inline style in the admin view. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
2026-08-13 17:03:43 +01:00
if (! is_string($rawToken) || $rawToken === '') {
return null;
}
return self::where('token_hash', hash('sha256', $rawToken))
->whereNull('revoked_at')
->first();
}
protected function isRevoked(): Attribute
{
return Attribute::make(
get: fn () => $this->revoked_at !== null,
);
}
}