Tokens now store a hashed row in micropub_tokens instead of being self-contained signed JWTs, so a leaked or unwanted token can actually be revoked. Since revocation already requires a DB lookup on every request, JWT's stateless-verification benefit was gone anyway, so this also drops the lcobucci/jwt dependency entirely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
30 lines
648 B
PHP
30 lines
648 B
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Services;
|
|
|
|
use App\Jobs\AddClientToDatabase;
|
|
use App\Models\MicropubToken;
|
|
|
|
class TokenService
|
|
{
|
|
/**
|
|
* Generate a new bearer token.
|
|
*/
|
|
public function getNewToken(array $data): string
|
|
{
|
|
$token = rtrim(strtr(base64_encode(random_bytes(32)), '+/', '-_'), '=');
|
|
|
|
MicropubToken::create([
|
|
'token_hash' => hash('sha256', $token),
|
|
'client_id' => $data['client_id'],
|
|
'me' => $data['me'],
|
|
'scope' => $data['scope'],
|
|
]);
|
|
|
|
dispatch(new AddClientToDatabase($data['client_id']));
|
|
|
|
return $token;
|
|
}
|
|
}
|