fix: add safe clock diagnostics to debug reports

This commit is contained in:
2026-08-24 09:53:16 +03:30
parent 656fc907a9
commit 322f484144
6 changed files with 282 additions and 24 deletions
@@ -10,10 +10,16 @@ use UnexpectedValueException;
class AuthenticateController extends InvocableController
{
private array $debugContext = [];
public function __invoke(MahakAuthenticateRequest $request)
{
$token = $request->string('token');
if (mahak_debug_enabled()) {
$this->debugContext['jwt_timestamps'] = $this->inspectJwtTimestamps($token);
}
$payload = $this->decrypt_jwt_token($token);
$identifier_name = get_configured_option('user-identifier');
@@ -85,7 +91,36 @@ class AuthenticateController extends InvocableController
$status = $exception->getCode() === 403 ? 403 : 500;
$fallbackView = $exception instanceof UnexpectedValueException ? 'invalid-token' : 'server-error';
mahak_render_error($exception, $status, $fallbackView);
mahak_render_error($exception, $status, $fallbackView, $this->debugContext);
}
private function inspectJwtTimestamps(string $token): array
{
$segments = explode('.', $token);
if (count($segments) !== 3) {
return [];
}
$encodedPayload = strtr($segments[1], '-_', '+/');
$encodedPayload .= str_repeat('=', (4 - strlen($encodedPayload) % 4) % 4);
$json = base64_decode($encodedPayload, true);
$payload = $json === false ? null : json_decode($json, true);
if (!is_array($payload)) {
return [];
}
$timestamps = [];
foreach (['iat', 'nbf', 'exp'] as $claim) {
if (array_key_exists($claim, $payload)) {
$value = is_scalar($payload[$claim]) ? (string) $payload[$claim] : '[non-scalar]';
$timestamps[$claim] = strlen($value) > 64 ? substr($value, 0, 64).'…' : $value;
}
}
return $timestamps;
}