Replace JWT Micropub tokens with revocable opaque tokens

Tokens now store a hashed row in micropub_tokens instead of being
self-contained signed JWTs, so a leaked or unwanted token can actually
be revoked. Since revocation already requires a DB lookup on every
request, JWT's stateless-verification benefit was gone anyway, so this
also drops the lcobucci/jwt dependency entirely.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
This commit is contained in:
Jonny Barnes 2026-08-13 16:07:07 +01:00
commit d5706b5f8f
Signed by: jonny
SSH key fingerprint: SHA256:CTuSlns5U7qlD9jqHvtnVmfYV3Zwl2Z7WnJ4/dqOaL8
10 changed files with 124 additions and 181 deletions

View file

@ -5,28 +5,26 @@ declare(strict_types=1);
namespace App\Services;
use App\Jobs\AddClientToDatabase;
use DateTimeImmutable;
use Lcobucci\JWT\Configuration;
use App\Models\MicropubToken;
class TokenService
{
/**
* Generate a JWT token.
* Generate a new bearer token.
*/
public function getNewToken(array $data): string
{
$config = resolve(Configuration::class);
$token = rtrim(strtr(base64_encode(random_bytes(32)), '+/', '-_'), '=');
$token = $config->builder()
->issuedAt(new DateTimeImmutable)
->withClaim('client_id', $data['client_id'])
->withClaim('me', $data['me'])
->withClaim('scope', $data['scope'])
->withClaim('nonce', bin2hex(random_bytes(8)))
->getToken($config->signer(), $config->signingKey());
MicropubToken::create([
'token_hash' => hash('sha256', $token),
'client_id' => $data['client_id'],
'me' => $data['me'],
'scope' => $data['scope'],
]);
dispatch(new AddClientToDatabase($data['client_id']));
return $token->toString();
return $token;
}
}