Commit da9a193
authored
Fix prod-mode asserts, middleware exception routing, redirect GET guard (#330)
* Replace assert() in AuthorizationService with explicit exception throws
The three assert() calls in performCheck(), getCanHandler() and
getScopeHandler() are compiled out when PHP runs with zend.assertions=-1,
the standard production setting. Under that configuration a missing policy
method silently falls through to the callable invocation and throws a
generic Error instead of MissingMethodException, and an invalid policy
return value flows on and causes a downstream type error.
Convert the three checks to explicit if/throw so the documented exceptions
fire in both development and production.
* Route policy exceptions through unauthorizedHandler in RequestAuthorizationMiddleware
The call to AuthorizationService::canResult() sat outside the try/catch
block, so any Authorization\Exception\Exception thrown from inside a
RequestPolicy (e.g. MissingMethodException, a custom MissingIdentityException
raised by canAccess(), or another policy-level failure) bypassed the
configured unauthorizedHandler and bubbled out of the middleware unhandled.
Move the canResult() call inside the try block to match the symmetry of
AuthorizationMiddleware, so all policy-level exceptions are routed through
the handler. Add a regression test using the Suppress handler.
* Honor GET-only guard in CakeRedirectHandler::getUrl()
The parent RedirectHandler::getUrl() guards the redirect query-param
appendage with a GET method check, so POST/PUT/DELETE/PATCH unauthorized
responses do not receive a useless `?redirect=` payload that clients cannot
follow. The Cake-flavoured override dropped that guard and appended the
query param for every method.
Mirror the parent behavior and add a data-provider test covering all
common non-GET methods.
* Add regression test for invalid return type from policy method
Covers the explicit-throw branch added in AuthorizationService::performCheck()
when a policy method returns a value that is neither bool nor a
ResultInterface. Adds a canInvalidReturnType() helper to ArticlePolicy
returning a plain string and asserts the documented exception fires.1 parent 21614bb commit da9a193
7 files changed
Lines changed: 104 additions & 15 deletions
File tree
- src
- Middleware
- UnauthorizedHandler
- tests
- TestCase
- Middleware
- UnauthorizedHandler
- test_app/TestApp/Policy
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
94 | 94 | | |
95 | 95 | | |
96 | 96 | | |
97 | | - | |
98 | | - | |
99 | | - | |
| 97 | + | |
| 98 | + | |
100 | 99 | | |
101 | 100 | | |
102 | | - | |
103 | | - | |
| 101 | + | |
| 102 | + | |
104 | 103 | | |
105 | 104 | | |
106 | 105 | | |
| |||
138 | 137 | | |
139 | 138 | | |
140 | 139 | | |
141 | | - | |
142 | | - | |
143 | | - | |
144 | | - | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
145 | 143 | | |
146 | 144 | | |
147 | 145 | | |
| |||
159 | 157 | | |
160 | 158 | | |
161 | 159 | | |
162 | | - | |
163 | | - | |
164 | | - | |
165 | | - | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
166 | 163 | | |
167 | 164 | | |
168 | 165 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
98 | 98 | | |
99 | 99 | | |
100 | 100 | | |
101 | | - | |
102 | 101 | | |
| 102 | + | |
103 | 103 | | |
104 | 104 | | |
105 | 105 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
68 | 68 | | |
69 | 69 | | |
70 | 70 | | |
71 | | - | |
| 71 | + | |
72 | 72 | | |
73 | 73 | | |
74 | 74 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| 20 | + | |
20 | 21 | | |
21 | 22 | | |
22 | 23 | | |
| |||
539 | 540 | | |
540 | 541 | | |
541 | 542 | | |
| 543 | + | |
| 544 | + | |
| 545 | + | |
| 546 | + | |
| 547 | + | |
| 548 | + | |
| 549 | + | |
| 550 | + | |
| 551 | + | |
| 552 | + | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
| 556 | + | |
| 557 | + | |
| 558 | + | |
| 559 | + | |
| 560 | + | |
542 | 561 | | |
Lines changed: 28 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
146 | 146 | | |
147 | 147 | | |
148 | 148 | | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
149 | 177 | | |
Lines changed: 36 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| 25 | + | |
25 | 26 | | |
26 | 27 | | |
27 | 28 | | |
| |||
150 | 151 | | |
151 | 152 | | |
152 | 153 | | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
153 | 189 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
141 | 141 | | |
142 | 142 | | |
143 | 143 | | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
144 | 153 | | |
0 commit comments