Fix CSRF exemption and array-input crash on revocation/introspection

An Opus code review of the branch caught two real bugs the test suite
structurally couldn't see:

- /revocation and /introspect were never added to bootstrap/app.php's
  CSRF except list, so both were fully broken (403) for any real
  external client, despite every feature test passing — CSRF
  verification is short-circuited entirely while running tests.
  Verified live against the running app before and after the fix, and
  added a regression test that asserts against the actual configured
  exemptions rather than relying on request-time behavior that tests
  can't exercise.

- An array-shaped `token` param (e.g. token[]=a&token[]=b) crashed
  both endpoints with a 500, since this app promotes PHP warnings
  ("Array to string conversion") to exceptions. Fixed at the shared
  root, MicropubToken::findActive(), which also closes the same latent
  hole in VerifyMicropubToken's access_token param that predates this
  branch. Verified live and covered with regression tests.

Also applied the review's lower-severity findings: added the missing
introspection_endpoint Link header and metadata test assertions,
removed the now-dead is_string($scopes) array branch in the Micropub
handlers and media controller (scope is unconditionally a string from
the DB now, this guarded against a JWT-array-claim shape that can no
longer occur), dropped a redundant #[Table] model attribute, sized
token_hash to its actual 64-char length, and removed a one-off inline
style in the admin view.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
This commit is contained in:
Jonny Barnes 2026-08-13 17:03:43 +01:00
commit faf8e5c1ec
Signed by: jonny
SSH key fingerprint: SHA256:CTuSlns5U7qlD9jqHvtnVmfYV3Zwl2Z7WnJ4/dqOaL8
14 changed files with 98 additions and 31 deletions

View file

@ -188,7 +188,7 @@ class IndieAuthController extends Controller
*/
public function processRevocationRequest(Request $request): JsonResponse
{
MicropubToken::findActive($request->get('token', ''))?->revoke();
MicropubToken::findActive($request->get('token'))?->revoke();
return response()->json([], 200);
}
@ -205,11 +205,11 @@ class IndieAuthController extends Controller
*/
public function processIntrospectionRequest(Request $request): JsonResponse
{
if (! MicropubToken::findActive((string) $request->bearerToken())) {
if (! MicropubToken::findActive($request->bearerToken())) {
return response()->json([], 401);
}
$token = MicropubToken::findActive((string) $request->get('token', ''));
$token = MicropubToken::findActive($request->get('token'));
if (! $token) {
return response()->json(['active' => false]);

View file

@ -26,9 +26,7 @@ class MicropubMediaController extends Controller
$tokenData = $request->input('token_data');
$scopes = $tokenData['scope'];
if (is_string($scopes)) {
$scopes = explode(' ', $scopes);
}
$scopes = explode(' ', $scopes);
if (! in_array('create', $scopes, true)) {
return (new MicropubResponses)->insufficientScopeResponse();
}
@ -84,9 +82,7 @@ class MicropubMediaController extends Controller
$tokenData = $request->input('token_data');
$scopes = $tokenData['scope'];
if (is_string($scopes)) {
$scopes = explode(' ', $scopes);
}
$scopes = explode(' ', $scopes);
if (! in_array('create', $scopes, true)) {
return (new MicropubResponses)->insufficientScopeResponse();
}

View file

@ -18,6 +18,7 @@ class LinkHeadersMiddleware
$response->header('Link', '<'.route('indieauth.start').'>; rel="authorization_endpoint"', false);
$response->header('Link', '<'.route('indieauth.token').'>; rel="token_endpoint"', false);
$response->header('Link', '<'.route('indieauth.revocation').'>; rel="revocation_endpoint"', false);
$response->header('Link', '<'.route('indieauth.introspection').'>; rel="introspection_endpoint"', false);
$response->header('Link', '<'.route('micropub-endpoint').'>; rel="micropub"', false);
$response->header('Link', '<'.route('webmention-endpoint').'>; rel="webmention"', false);

View file

@ -5,11 +5,9 @@ declare(strict_types=1);
namespace App\Models;
use Illuminate\Database\Eloquent\Attributes\Fillable;
use Illuminate\Database\Eloquent\Attributes\Table;
use Illuminate\Database\Eloquent\Casts\Attribute;
use Illuminate\Database\Eloquent\Model;
#[Table('micropub_tokens')]
#[Fillable(['token_hash', 'client_id', 'me', 'scope'])]
class MicropubToken extends Model
{
@ -26,11 +24,15 @@ class MicropubToken extends Model
}
/**
* Find the active (non-revoked) token matching a raw bearer token string.
* Find the active (non-revoked) token matching a raw bearer token value.
*
* Accepts mixed because callers pass request input directly, which PHP
* lets be an array (e.g. a client sending token[]=a) - casting that to
* string would throw, so anything non-string is just treated as absent.
*/
public static function findActive(string $rawToken): ?self
public static function findActive(mixed $rawToken): ?self
{
if ($rawToken === '') {
if (! is_string($rawToken) || $rawToken === '') {
return null;
}

View file

@ -24,9 +24,7 @@ class CardHandler implements MicropubHandlerInterface
assert($data instanceof CardData);
$scopes = $data->tokenData['scope'];
if (is_string($scopes)) {
$scopes = explode(' ', $scopes);
}
$scopes = explode(' ', $scopes);
if (! in_array('create', $scopes, true)) {
throw new InvalidTokenScopeException;

View file

@ -27,9 +27,7 @@ class EntryHandler implements MicropubHandlerInterface
assert($data instanceof EntryData);
$scopes = $data->tokenData['scope'];
if (is_string($scopes)) {
$scopes = explode(' ', $scopes);
}
$scopes = explode(' ', $scopes);
if (! in_array('create', $scopes, true)) {
throw new InvalidTokenScopeException;

View file

@ -30,9 +30,7 @@ class UpdateHandler implements MicropubHandlerInterface
assert($data instanceof UpdateData);
$scopes = $data->tokenData['scope'];
if (is_string($scopes)) {
$scopes = explode(' ', $scopes);
}
$scopes = explode(' ', $scopes);
if (! in_array('update', $scopes, true)) {
throw new InvalidTokenScopeException;