jonnybarnes.uk/app
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jonny Barnes 24da24a677
Add IndieAuth token introspection endpoint (RFC 7662)
Lets a resource server (or a client checking its own token, via
self-introspection) verify a token's active/me/client_id/scope without
needing to be tightly coupled to this token endpoint. Requires the
caller to present their own currently-active token as authorization,
per spec's requirement that the endpoint MUST require some form of
authorization. Inactive tokens get back only {"active": false}, no
detail on why, matching the privacy stance already used for
revocation.

Pulled the hash-and-lookup-active-token logic (now needed a third
time) into MicropubToken::findActive(), used by this, the revocation
endpoint, and VerifyMicropubToken.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
2026-08-13 16:44:31 +01:00
..
CommonMark Upgrade to Laravel 13 2026-04-07 09:01:19 +01:00
Console Adopt Laravel's Image facade for media processing, upgrade Intervention to v4 2026-08-01 17:07:38 +01:00
Exceptions Implement micropub update support with clean exception-based error handling 2026-02-22 10:15:35 +00:00
Http Add IndieAuth token introspection endpoint (RFC 7662) 2026-08-13 16:44:31 +01:00
Jobs Send Brrr push notifications for new webmentions 2026-08-02 18:07:39 +01:00
Models Add IndieAuth token introspection endpoint (RFC 7662) 2026-08-13 16:44:31 +01:00
Observers Remove psalm annotations 2025-04-10 20:09:36 +01:00
Providers Replace JWT Micropub tokens with revocable opaque tokens 2026-08-13 16:07:07 +01:00
Services Replace JWT Micropub tokens with revocable opaque tokens 2026-08-13 16:07:07 +01:00
Traits Switch to Symfony’s HTML Sanitizer package 2022-06-02 09:40:34 +01:00