fix: add safe clock diagnostics to debug reports
This commit is contained in:
@@ -258,11 +258,20 @@ function test_debug_error_details(): void
|
||||
{
|
||||
update_option('mahak_debug_mode', 1);
|
||||
|
||||
$response = http_request(TEST_SITE_URL.'/mahak/login/?token=not-a-jwt');
|
||||
$futureIat = time() + 300;
|
||||
$token = make_jwt([
|
||||
'iat' => $futureIat,
|
||||
'exp' => $futureIat + 600,
|
||||
'data' => [
|
||||
'name' => 'Future User',
|
||||
'email' => 'future-user@example.test',
|
||||
],
|
||||
], TEST_SECRET);
|
||||
$response = http_request(TEST_SITE_URL.'/mahak/login/?token='.rawurlencode($token));
|
||||
|
||||
assert_true($response['status'] === 500, 'Debug error response should return HTTP 500.');
|
||||
assert_true(
|
||||
strpos($response['body'], 'JWT must contain header, payload, and signature.') !== false,
|
||||
strpos($response['body'], 'JWT cannot be used before iat.') !== false,
|
||||
'Debug response did not contain the underlying exception message.'
|
||||
);
|
||||
assert_true(
|
||||
@@ -270,12 +279,33 @@ function test_debug_error_details(): void
|
||||
'Debug response did not contain the exception class.'
|
||||
);
|
||||
assert_true(
|
||||
strpos($response['body'], 'Stack trace') !== false,
|
||||
'Debug response did not contain a stack trace.'
|
||||
strpos($response['body'], 'WordPress server diagnostics') !== false
|
||||
&& strpos($response['body'], 'Unix timestamp') !== false
|
||||
&& strpos($response['body'], 'WordPress timezone') !== false,
|
||||
'Debug response did not contain WordPress server clock and timezone details.'
|
||||
);
|
||||
assert_true(
|
||||
strpos($response['body'], 'JWT timing claims') !== false
|
||||
&& strpos($response['body'], (string) $futureIat) !== false
|
||||
&& strpos($response['body'], 'seconds vs server') !== false,
|
||||
'Debug response did not contain safe JWT timing diagnostics.'
|
||||
);
|
||||
assert_true(
|
||||
strpos($response['body'], 'Copy Markdown') !== false
|
||||
&& strpos($response['body'], '# Mahak Authentication Error') !== false,
|
||||
'Debug response did not contain a copyable Markdown report.'
|
||||
);
|
||||
assert_true(
|
||||
strpos($response['body'], TEST_SECRET) === false && strpos($response['body'], $token) === false,
|
||||
'Debug response exposed the JWT token or signing secret.'
|
||||
);
|
||||
assert_true(
|
||||
strpos($response['body'], 'Sanitized stack trace') !== false,
|
||||
'Debug response did not contain the sanitized stack trace.'
|
||||
);
|
||||
|
||||
update_option('mahak_debug_mode', 0);
|
||||
pass('Debug mode displays full exception details and stack trace');
|
||||
pass('Debug report includes clock diagnostics and Markdown without token or secret leakage');
|
||||
}
|
||||
|
||||
function test_plugin_update_discovery(): void
|
||||
|
||||
Reference in New Issue
Block a user