Implements the current IndieAuth spec's dedicated /revocation endpoint so clients can self-revoke a token (e.g. on user sign-out), rather than only supporting revocation via the admin side. Always responds 200 per spec, whether the token was found or not, so callers can't use it to probe token validity. Skips the legacy action=revoke-on-/token fallback the spec mentions for older clients, since the only real client here is already being updated to use the current endpoint. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
26 lines
967 B
PHP
26 lines
967 B
PHP
<?php
|
|
|
|
namespace App\Http\Middleware;
|
|
|
|
use Closure;
|
|
use Illuminate\Http\Request;
|
|
use Symfony\Component\HttpFoundation\Response;
|
|
|
|
class LinkHeadersMiddleware
|
|
{
|
|
/**
|
|
* Handle an incoming request.
|
|
*/
|
|
public function handle(Request $request, Closure $next): Response
|
|
{
|
|
$response = $next($request);
|
|
$response->header('Link', '<'.route('indieauth.metadata').'>; rel="indieauth-metadata"', false);
|
|
$response->header('Link', '<'.route('indieauth.start').'>; rel="authorization_endpoint"', false);
|
|
$response->header('Link', '<'.route('indieauth.token').'>; rel="token_endpoint"', false);
|
|
$response->header('Link', '<'.route('indieauth.revocation').'>; rel="revocation_endpoint"', false);
|
|
$response->header('Link', '<'.route('micropub-endpoint').'>; rel="micropub"', false);
|
|
$response->header('Link', '<'.route('webmention-endpoint').'>; rel="webmention"', false);
|
|
|
|
return $response;
|
|
}
|
|
}
|