jonnybarnes.uk/resources/views
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jonny Barnes faf8e5c1ec
Fix CSRF exemption and array-input crash on revocation/introspection
An Opus code review of the branch caught two real bugs the test suite
structurally couldn't see:

- /revocation and /introspect were never added to bootstrap/app.php's
  CSRF except list, so both were fully broken (403) for any real
  external client, despite every feature test passing — CSRF
  verification is short-circuited entirely while running tests.
  Verified live against the running app before and after the fix, and
  added a regression test that asserts against the actual configured
  exemptions rather than relying on request-time behavior that tests
  can't exercise.

- An array-shaped `token` param (e.g. token[]=a&token[]=b) crashed
  both endpoints with a 500, since this app promotes PHP warnings
  ("Array to string conversion") to exceptions. Fixed at the shared
  root, MicropubToken::findActive(), which also closes the same latent
  hole in VerifyMicropubToken's access_token param that predates this
  branch. Verified live and covered with regression tests.

Also applied the review's lower-severity findings: added the missing
introspection_endpoint Link header and metadata test assertions,
removed the now-dead is_string($scopes) array branch in the Micropub
handlers and media controller (scope is unconditionally a string from
the DB now, this guarded against a JWT-array-claim shape that can no
longer occur), dropped a redundant #[Table] model attribute, sized
token_hash to its actual 64-char length, and removed a one-off inline
style in the admin view.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
2026-08-13 17:03:43 +01:00
..
admin Fix CSRF exemption and array-input crash on revocation/introspection 2026-08-13 17:03:43 +01:00
articles Remove references to short domain 2025-04-06 17:22:36 +01:00
bookmarks Upgrade to Laravel 13 2026-04-07 09:01:19 +01:00
contacts Ooof, got the dependencies all up to date as well 2019-10-27 16:15:14 +00:00
errors Modify maintenance page 2017-02-16 10:02:58 +00:00
icons Fix layout of note metadata 2025-12-11 17:48:42 +00:00
indieauth Auth endpoint 2024-06-02 10:16:16 +01:00
likes Remove Twitter POSSE support 2023-04-08 13:25:36 +01:00
notes Replace abandoned spatie/commonmark-highlighter with tempest/highlight 2026-07-14 18:37:05 +01:00
templates Switch Bridgy syndication from Micropub to webmention 2026-07-14 17:36:25 +01:00
vendor Initial commit to new repo 2016-05-19 15:01:28 +01:00
allplaces.blade.php Ooof, got the dependencies all up to date as well 2019-10-27 16:15:14 +00:00
colophon.blade.php Improve colophon page 2022-08-20 14:05:59 +01:00
front-page.blade.php Switch bio to be stored in database 2023-04-11 17:37:42 +01:00
login.blade.php Some fixes related to developing my Micropub client 2025-08-17 11:05:38 +01:00
logout.blade.php Protect admin routes with new eloquent sessions 2019-03-23 09:35:07 +00:00
master.blade.php Replace abandoned spatie/commonmark-highlighter with tempest/highlight 2026-07-14 18:37:05 +01:00
projects.blade.php New style for the website 2017-11-04 12:10:46 +00:00
search.blade.php Re-add search functionality 2023-04-11 21:44:55 +01:00
singleplace.blade.php Remove mapbox links 2023-05-04 18:32:07 +01:00
webmention-endpoint.blade.php Ooof, got the dependencies all up to date as well 2019-10-27 16:15:14 +00:00
welcome.blade.php Squashed commit of the following: 2017-08-11 21:02:03 +01:00