fix: add safe clock diagnostics to debug reports

This commit is contained in:
2026-08-24 09:53:16 +03:30
parent 656fc907a9
commit 322f484144
6 changed files with 282 additions and 24 deletions
+35 -5
View File
@@ -258,11 +258,20 @@ function test_debug_error_details(): void
{
update_option('mahak_debug_mode', 1);
$response = http_request(TEST_SITE_URL.'/mahak/login/?token=not-a-jwt');
$futureIat = time() + 300;
$token = make_jwt([
'iat' => $futureIat,
'exp' => $futureIat + 600,
'data' => [
'name' => 'Future User',
'email' => 'future-user@example.test',
],
], TEST_SECRET);
$response = http_request(TEST_SITE_URL.'/mahak/login/?token='.rawurlencode($token));
assert_true($response['status'] === 500, 'Debug error response should return HTTP 500.');
assert_true(
strpos($response['body'], 'JWT must contain header, payload, and signature.') !== false,
strpos($response['body'], 'JWT cannot be used before iat.') !== false,
'Debug response did not contain the underlying exception message.'
);
assert_true(
@@ -270,12 +279,33 @@ function test_debug_error_details(): void
'Debug response did not contain the exception class.'
);
assert_true(
strpos($response['body'], 'Stack trace') !== false,
'Debug response did not contain a stack trace.'
strpos($response['body'], 'WordPress server diagnostics') !== false
&& strpos($response['body'], 'Unix timestamp') !== false
&& strpos($response['body'], 'WordPress timezone') !== false,
'Debug response did not contain WordPress server clock and timezone details.'
);
assert_true(
strpos($response['body'], 'JWT timing claims') !== false
&& strpos($response['body'], (string) $futureIat) !== false
&& strpos($response['body'], 'seconds vs server') !== false,
'Debug response did not contain safe JWT timing diagnostics.'
);
assert_true(
strpos($response['body'], 'Copy Markdown') !== false
&& strpos($response['body'], '# Mahak Authentication Error') !== false,
'Debug response did not contain a copyable Markdown report.'
);
assert_true(
strpos($response['body'], TEST_SECRET) === false && strpos($response['body'], $token) === false,
'Debug response exposed the JWT token or signing secret.'
);
assert_true(
strpos($response['body'], 'Sanitized stack trace') !== false,
'Debug response did not contain the sanitized stack trace.'
);
update_option('mahak_debug_mode', 0);
pass('Debug mode displays full exception details and stack trace');
pass('Debug report includes clock diagnostics and Markdown without token or secret leakage');
}
function test_plugin_update_discovery(): void