Laravel based code that runs my personal website https://jonnybarnes.uk
  • PHP 82.7%
  • Blade 14.2%
  • JavaScript 1.7%
  • CSS 1.2%
  • HTML 0.1%
  • Other 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jonny Barnes faf8e5c1ec
Fix CSRF exemption and array-input crash on revocation/introspection
An Opus code review of the branch caught two real bugs the test suite
structurally couldn't see:

- /revocation and /introspect were never added to bootstrap/app.php's
  CSRF except list, so both were fully broken (403) for any real
  external client, despite every feature test passing — CSRF
  verification is short-circuited entirely while running tests.
  Verified live against the running app before and after the fix, and
  added a regression test that asserts against the actual configured
  exemptions rather than relying on request-time behavior that tests
  can't exercise.

- An array-shaped `token` param (e.g. token[]=a&token[]=b) crashed
  both endpoints with a 500, since this app promotes PHP warnings
  ("Array to string conversion") to exceptions. Fixed at the shared
  root, MicropubToken::findActive(), which also closes the same latent
  hole in VerifyMicropubToken's access_token param that predates this
  branch. Verified live and covered with regression tests.

Also applied the review's lower-severity findings: added the missing
introspection_endpoint Link header and metadata test assertions,
removed the now-dead is_string($scopes) array branch in the Micropub
handlers and media controller (scope is unconditionally a string from
the DB now, this guarded against a JWT-array-claim shape that can no
longer occur), dropped a redundant #[Table] model attribute, sized
token_hash to its actual 64-char length, and removed a one-off inline
style in the admin view.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
2026-08-13 17:03:43 +01:00
app Fix CSRF exemption and array-input crash on revocation/introspection 2026-08-13 17:03:43 +01:00
bootstrap Fix CSRF exemption and array-input crash on revocation/introspection 2026-08-13 17:03:43 +01:00
config Send Brrr push notifications for new webmentions 2026-08-02 18:07:39 +01:00
database Fix CSRF exemption and array-input crash on revocation/introspection 2026-08-13 17:03:43 +01:00
public Update dependencies 2026-07-26 10:57:20 +01:00
resources Fix CSRF exemption and array-input crash on revocation/introspection 2026-08-13 17:03:43 +01:00
routes Add IndieAuth token introspection endpoint (RFC 7662) 2026-08-13 16:44:31 +01:00
scripts Redesign v2025.1 2025-12-11 17:17:01 +00:00
storage Host images locally 2024-10-25 20:40:52 +01:00
tests Fix CSRF exemption and array-input crash on revocation/introspection 2026-08-13 17:03:43 +01:00
.editorconfig Initial work on adding passkeys 2023-08-25 13:43:51 +01:00
.env.example Send Brrr push notifications for new webmentions 2026-08-02 18:07:39 +01:00
.gitattributes Remove un-needed config files 2025-04-10 21:03:22 +01:00
.gitignore Remove un-needed config files 2025-04-10 21:03:22 +01:00
.stylelintrc Initial work on adding passkeys 2023-08-25 13:43:51 +01:00
artisan Upgrade to Laravel 11 2024-03-19 20:13:36 +00:00
composer.json Replace JWT Micropub tokens with revocable opaque tokens 2026-08-13 16:07:07 +01:00
composer.lock Replace JWT Micropub tokens with revocable opaque tokens 2026-08-13 16:07:07 +01:00
docker-compose.yml Switch local setup to PHP8.5 2025-12-13 15:53:00 +00:00
eslint.config.js Update eslint config 2024-06-08 20:55:34 +01:00
helpers.php Upgrade to Laravel 13 2026-04-07 09:01:19 +01:00
jbuk_dev_backup.dump Update dependencies 2026-02-21 17:06:37 +00:00
license.md Add a license file 2016-09-17 21:20:57 +01:00
package-lock.json Update dependencies 2026-07-26 10:57:20 +01:00
package.json Update dependencies 2026-06-29 20:13:11 +01:00
phpcs.xml Fixing various phpcs issues 2019-10-27 19:31:33 +00:00
phpunit.xml Update dependencies 2024-10-23 09:16:11 +01:00
pint.json Upgrade to Laravel 13 2026-04-07 09:01:19 +01:00
readme.md Tweak the readme 2023-04-08 16:18:02 +01:00
server.php Fix files with Laravel Pint 2022-07-09 10:08:26 +01:00

jonnybarnes.uk

This is the code that runs my website, jonnybarnes.uk.

In theory this is usable by others now 🚀

Set up the database, this software needs PostgreSQL, after installing:

$ createdb -E utf8 db_name

First get the code, and make sure youre on the master branch. This branch will only have tagged releases:

$ git clone https://github.com/jonnybarnes/jonnybarnes.uk mysite.com
$ cd mysite.com
$ git checkout master

Then we need to set up the environment variables that the app will use.

$ cp .env.example .env
$ vim .env

Fill in the various variables. Then we can set up the app:

$ composer install
$ php artisan key:generate
$ php artisan migrate

Now we need to edit some config values. In config/app.php edit name.

Some other things that should be changed. Go to resources/views/master.blade.php, you may not want to link to a projects page. Also in the <head> the two last links are to my profile pic and pgp key, ammend/remove as desired.

Now point your server to public/index.php et viola. Essentially this is a Laravel app so debugging things shouldnt be too hard.