An Opus code review of the branch caught two real bugs the test suite
structurally couldn't see:
- /revocation and /introspect were never added to bootstrap/app.php's
CSRF except list, so both were fully broken (403) for any real
external client, despite every feature test passing — CSRF
verification is short-circuited entirely while running tests.
Verified live against the running app before and after the fix, and
added a regression test that asserts against the actual configured
exemptions rather than relying on request-time behavior that tests
can't exercise.
- An array-shaped `token` param (e.g. token[]=a&token[]=b) crashed
both endpoints with a 500, since this app promotes PHP warnings
("Array to string conversion") to exceptions. Fixed at the shared
root, MicropubToken::findActive(), which also closes the same latent
hole in VerifyMicropubToken's access_token param that predates this
branch. Verified live and covered with regression tests.
Also applied the review's lower-severity findings: added the missing
introspection_endpoint Link header and metadata test assertions,
removed the now-dead is_string($scopes) array branch in the Micropub
handlers and media controller (scope is unconditionally a string from
the DB now, this guarded against a JWT-array-claim shape that can no
longer occur), dropped a redundant #[Table] model attribute, sized
token_hash to its actual 64-char length, and removed a one-off inline
style in the admin view.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
Lets a resource server (or a client checking its own token, via
self-introspection) verify a token's active/me/client_id/scope without
needing to be tightly coupled to this token endpoint. Requires the
caller to present their own currently-active token as authorization,
per spec's requirement that the endpoint MUST require some form of
authorization. Inactive tokens get back only {"active": false}, no
detail on why, matching the privacy stance already used for
revocation.
Pulled the hash-and-lookup-active-token logic (now needed a third
time) into MicropubToken::findActive(), used by this, the revocation
endpoint, and VerifyMicropubToken.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
Implements the current IndieAuth spec's dedicated /revocation endpoint
so clients can self-revoke a token (e.g. on user sign-out), rather than
only supporting revocation via the admin side. Always responds 200 per
spec, whether the token was found or not, so callers can't use it to
probe token validity. Skips the legacy action=revoke-on-/token fallback
the spec mentions for older clients, since the only real client here is
already being updated to use the current endpoint.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
Tokens now store a hashed row in micropub_tokens instead of being
self-contained signed JWTs, so a leaked or unwanted token can actually
be revoked. Since revocation already requires a DB lookup on every
request, JWT's stateless-verification benefit was gone anyway, so this
also drops the lcobucci/jwt dependency entirely.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
Trying to organise the code better. It now temporarily doesn’t support
update requests. Thought the spec defines them as SHOULD features and
not MUST features. So safe for now :)
- Update various factory files in the `database/factories` directory
- Remove unused imports and annotations in factory files
- Add or update comments and PHPDoc blocks for better understanding and readability
- Remove unused imports in controller and command files
- Remove commented out code in middleware file
When using Laravel’s own auth middleware an exception would then get
thrown which was being sent to Slack, hmmm.
So I modified the original MyAuthMiddleware to use the Auth facade
instead of a custom session key.
A logout page has also been added.
Squashed commit of the following:
commit 468945826621d2e586f7e5fa773623c4accc316a
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Fri Mar 2 16:42:30 2018 +0000
Update changelog
commit 36c6edce091c41861879a982e6ad250b395abbcf
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Fri Mar 2 16:42:23 2018 +0000
Add a test
commit ef9d7b564f8ea4f4528c42f411c14ddfaa132082
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Fri Mar 2 16:42:13 2018 +0000
Apply the CSPHeader middleware to all `web` requests
commit 737bfca3a6b446d52c0d0a8cc1b7b1c422876c0b
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Fri Mar 2 16:41:45 2018 +0000
Add a CSP header to a response, as well as the Report-To header
Squashed commit of the following:
commit 0a620148dfad998f7b00804cae1db8208b23cc02
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Fri Mar 2 15:08:36 2018 +0000
Add tests for the Cors Headers
commit dd8518d279cdf3857597fa7ee6150bf383203fe1
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Fri Mar 2 15:08:20 2018 +0000
Only add Cors Headers to requests to the media endpoint
commit 6c79ca5632581345ef406f211b1576a4b7f400fe
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Fri Mar 2 15:07:53 2018 +0000
Add CorsHeaders to middleware array
commit e12d48ca1e837b14b75bbd87d6197d59d60cf32e
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Fri Mar 2 15:06:32 2018 +0000
We need to send something to the OPTIONS request to the media endpoint
commit f11c638be464373bff09bf015d4a989e48e61f0c
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Fri Mar 2 15:05:45 2018 +0000
Change routes to allow for responses to an OPTIONS request to the media endpoint
Squashed commit of the following:
commit 74ed84617fcbecf661695763323e50d049a88db7
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Mon Jan 15 12:46:29 2018 +0000
Test passes so remove the dump statement
commit a7d3323be02da64f76e8ec88713e3de84a13ded7
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Mon Jan 15 12:40:35 2018 +0000
Values with spaces need to be quoted
commit 58a120bb238f14346793c388b948b7351d3b51fd
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Mon Jan 15 12:37:23 2018 +0000
We need a diplay name for the tests to work now we are using strict type checking
commit b46f177053bd697db9a4835d073f2f37e088b26f
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Mon Jan 15 12:31:29 2018 +0000
Get travis to show more info about failing test
commit 60323f3ce5a0561329a1721ee94821571cdcc86a
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Mon Jan 15 12:23:27 2018 +0000
Remove un-used namnepsace imports
commit 096d3505920bc94ff8677c77430eca0aae0be58a
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Mon Jan 15 12:21:55 2018 +0000
we need php7.2 for object type-hint
commit bb818bc19c73d02d510af9f002199f5718a54608
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Mon Jan 15 12:15:48 2018 +0000
Added lots of strict_types
commit fcebc08f6d89437ba84288a25498ae094fd4f16d
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Wed Jan 10 21:59:33 2018 +0000
update changelog
commit 74491698857cb2e111006efb349e1f10c2e3cf1d
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Wed Jan 10 21:58:25 2018 +0000
Modify the micropub controller to look for the token in the right palce (as set by the token middleware
commit 0fd11ff8391062fbe70f3a28d6a98694dc25b36b
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Wed Jan 10 21:57:40 2018 +0000
If the access token is sent as a bearer token in the http headers, merge it into the request data so the controllers only have one place to look
commit 9e154ec4bc17be3071280409a3f6bb7f02dad816
Author: Jonny Barnes <jonny@jonnybarnes.uk>
Date: Wed Jan 10 21:56:33 2018 +0000
Add a test with the access token being form encoded