Fix CSRF exemption and array-input crash on revocation/introspection
An Opus code review of the branch caught two real bugs the test suite
structurally couldn't see:
- /revocation and /introspect were never added to bootstrap/app.php's
CSRF except list, so both were fully broken (403) for any real
external client, despite every feature test passing — CSRF
verification is short-circuited entirely while running tests.
Verified live against the running app before and after the fix, and
added a regression test that asserts against the actual configured
exemptions rather than relying on request-time behavior that tests
can't exercise.
- An array-shaped `token` param (e.g. token[]=a&token[]=b) crashed
both endpoints with a 500, since this app promotes PHP warnings
("Array to string conversion") to exceptions. Fixed at the shared
root, MicropubToken::findActive(), which also closes the same latent
hole in VerifyMicropubToken's access_token param that predates this
branch. Verified live and covered with regression tests.
Also applied the review's lower-severity findings: added the missing
introspection_endpoint Link header and metadata test assertions,
removed the now-dead is_string($scopes) array branch in the Micropub
handlers and media controller (scope is unconditionally a string from
the DB now, this guarded against a JWT-array-claim shape that can no
longer occur), dropped a redundant #[Table] model attribute, sized
token_hash to its actual 64-char length, and removed a one-off inline
style in the admin view.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
This commit is contained in:
parent
24da24a677
commit
faf8e5c1ec
14 changed files with 98 additions and 31 deletions
|
|
@ -188,7 +188,7 @@ class IndieAuthController extends Controller
|
|||
*/
|
||||
public function processRevocationRequest(Request $request): JsonResponse
|
||||
{
|
||||
MicropubToken::findActive($request->get('token', ''))?->revoke();
|
||||
MicropubToken::findActive($request->get('token'))?->revoke();
|
||||
|
||||
return response()->json([], 200);
|
||||
}
|
||||
|
|
@ -205,11 +205,11 @@ class IndieAuthController extends Controller
|
|||
*/
|
||||
public function processIntrospectionRequest(Request $request): JsonResponse
|
||||
{
|
||||
if (! MicropubToken::findActive((string) $request->bearerToken())) {
|
||||
if (! MicropubToken::findActive($request->bearerToken())) {
|
||||
return response()->json([], 401);
|
||||
}
|
||||
|
||||
$token = MicropubToken::findActive((string) $request->get('token', ''));
|
||||
$token = MicropubToken::findActive($request->get('token'));
|
||||
|
||||
if (! $token) {
|
||||
return response()->json(['active' => false]);
|
||||
|
|
|
|||
|
|
@ -26,9 +26,7 @@ class MicropubMediaController extends Controller
|
|||
$tokenData = $request->input('token_data');
|
||||
|
||||
$scopes = $tokenData['scope'];
|
||||
if (is_string($scopes)) {
|
||||
$scopes = explode(' ', $scopes);
|
||||
}
|
||||
$scopes = explode(' ', $scopes);
|
||||
if (! in_array('create', $scopes, true)) {
|
||||
return (new MicropubResponses)->insufficientScopeResponse();
|
||||
}
|
||||
|
|
@ -84,9 +82,7 @@ class MicropubMediaController extends Controller
|
|||
$tokenData = $request->input('token_data');
|
||||
|
||||
$scopes = $tokenData['scope'];
|
||||
if (is_string($scopes)) {
|
||||
$scopes = explode(' ', $scopes);
|
||||
}
|
||||
$scopes = explode(' ', $scopes);
|
||||
if (! in_array('create', $scopes, true)) {
|
||||
return (new MicropubResponses)->insufficientScopeResponse();
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue