feat: add admin-controlled authentication debug mode

This commit is contained in:
2026-08-23 16:01:09 +03:30
parent 6419f82ea5
commit 572a740d46
11 changed files with 187 additions and 42 deletions
+30 -1
View File
@@ -246,8 +246,36 @@ function test_invalid_authentication(): void
!header_contains($response['headers'], 'Set-Cookie: wordpress_logged_in_'),
'Invalid authentication request issued a logged-in cookie.'
);
assert_true(
strpos($response['body'], 'JWT signature is invalid.') === false,
'Debug details were exposed while debug mode was disabled.'
);
pass('Invalid JWT is rejected without login cookies');
pass('Invalid JWT is rejected without login cookies or debug details');
}
function test_debug_error_details(): void
{
update_option('mahak_debug_mode', 1);
$response = http_request(TEST_SITE_URL.'/mahak/login/?token=not-a-jwt');
assert_true($response['status'] === 500, 'Debug error response should return HTTP 500.');
assert_true(
strpos($response['body'], 'JWT must contain header, payload, and signature.') !== false,
'Debug response did not contain the underlying exception message.'
);
assert_true(
strpos($response['body'], 'UnexpectedValueException') !== false,
'Debug response did not contain the exception class.'
);
assert_true(
strpos($response['body'], 'Stack trace') !== false,
'Debug response did not contain a stack trace.'
);
update_option('mahak_debug_mode', 0);
pass('Debug mode displays full exception details and stack trace');
}
boot_wordpress();
@@ -256,5 +284,6 @@ activate_and_configure_plugin();
wait_for_http();
test_valid_authentication();
test_invalid_authentication();
test_debug_error_details();
echo "[OK] Authentication integration test passed\n";