An Opus code review of the branch caught two real bugs the test suite
structurally couldn't see:
- /revocation and /introspect were never added to bootstrap/app.php's
CSRF except list, so both were fully broken (403) for any real
external client, despite every feature test passing — CSRF
verification is short-circuited entirely while running tests.
Verified live against the running app before and after the fix, and
added a regression test that asserts against the actual configured
exemptions rather than relying on request-time behavior that tests
can't exercise.
- An array-shaped `token` param (e.g. token[]=a&token[]=b) crashed
both endpoints with a 500, since this app promotes PHP warnings
("Array to string conversion") to exceptions. Fixed at the shared
root, MicropubToken::findActive(), which also closes the same latent
hole in VerifyMicropubToken's access_token param that predates this
branch. Verified live and covered with regression tests.
Also applied the review's lower-severity findings: added the missing
introspection_endpoint Link header and metadata test assertions,
removed the now-dead is_string($scopes) array branch in the Micropub
handlers and media controller (scope is unconditionally a string from
the DB now, this guarded against a JWT-array-claim shape that can no
longer occur), dropped a redundant #[Table] model attribute, sized
token_hash to its actual 64-char length, and removed a one-off inline
style in the admin view.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014625MfkGZ7GVdbqKme4a8L
29 lines
983 B
PHP
29 lines
983 B
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace Tests\Feature;
|
|
|
|
use Illuminate\Foundation\Http\Middleware\PreventRequestForgery;
|
|
use PHPUnit\Framework\Attributes\Test;
|
|
use Tests\TestCase;
|
|
|
|
class CsrfExemptionsTest extends TestCase
|
|
{
|
|
/**
|
|
* CSRF verification is short-circuited entirely while running the test
|
|
* suite (see PreventRequestForgery::runningUnitTests()), so a normal
|
|
* feature test hitting these routes would pass even if they were never
|
|
* added to bootstrap/app.php's except list. Assert against the actual
|
|
* configured exemptions instead.
|
|
*/
|
|
#[Test]
|
|
public function external_api_endpoints_are_exempt_from_csrf_verification(): void
|
|
{
|
|
$exemptions = $this->app->make(PreventRequestForgery::class)->getExcludedPaths();
|
|
|
|
foreach (['auth', 'token', 'revocation', 'introspect', 'api/post', 'api/media', 'micropub/places', 'webmention'] as $path) {
|
|
$this->assertContains($path, $exemptions);
|
|
}
|
|
}
|
|
}
|