fix: add safe clock diagnostics to debug reports
This commit is contained in:
@@ -10,10 +10,16 @@ use UnexpectedValueException;
|
||||
|
||||
class AuthenticateController extends InvocableController
|
||||
{
|
||||
private array $debugContext = [];
|
||||
|
||||
public function __invoke(MahakAuthenticateRequest $request)
|
||||
{
|
||||
$token = $request->string('token');
|
||||
|
||||
if (mahak_debug_enabled()) {
|
||||
$this->debugContext['jwt_timestamps'] = $this->inspectJwtTimestamps($token);
|
||||
}
|
||||
|
||||
$payload = $this->decrypt_jwt_token($token);
|
||||
|
||||
$identifier_name = get_configured_option('user-identifier');
|
||||
@@ -85,7 +91,36 @@ class AuthenticateController extends InvocableController
|
||||
$status = $exception->getCode() === 403 ? 403 : 500;
|
||||
$fallbackView = $exception instanceof UnexpectedValueException ? 'invalid-token' : 'server-error';
|
||||
|
||||
mahak_render_error($exception, $status, $fallbackView);
|
||||
mahak_render_error($exception, $status, $fallbackView, $this->debugContext);
|
||||
}
|
||||
|
||||
private function inspectJwtTimestamps(string $token): array
|
||||
{
|
||||
$segments = explode('.', $token);
|
||||
|
||||
if (count($segments) !== 3) {
|
||||
return [];
|
||||
}
|
||||
|
||||
$encodedPayload = strtr($segments[1], '-_', '+/');
|
||||
$encodedPayload .= str_repeat('=', (4 - strlen($encodedPayload) % 4) % 4);
|
||||
$json = base64_decode($encodedPayload, true);
|
||||
$payload = $json === false ? null : json_decode($json, true);
|
||||
|
||||
if (!is_array($payload)) {
|
||||
return [];
|
||||
}
|
||||
|
||||
$timestamps = [];
|
||||
|
||||
foreach (['iat', 'nbf', 'exp'] as $claim) {
|
||||
if (array_key_exists($claim, $payload)) {
|
||||
$value = is_scalar($payload[$claim]) ? (string) $payload[$claim] : '[non-scalar]';
|
||||
$timestamps[$claim] = strlen($value) > 64 ? substr($value, 0, 64).'…' : $value;
|
||||
}
|
||||
}
|
||||
|
||||
return $timestamps;
|
||||
}
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user