chore: address Plan 4 deferred-minors (stale-cookie cleanup pass)
CI / php (push) Failing after 1m11s

- Rename $secret to $csrfSecret in public/index.php to make
  intent clear at every call site; the value is the CSRF/turn-token
  HMAC key, not just 'the secret'.
- Drop the stale 'Configure the router with the eight routes' comment
  in public/index.php; the router now has sixteen routes.
- Drop the duplicate .bf-toast rule in public/assets/styles.css; the
  second declaration (the new yellow box) is the active one, the
  first (legacy green pill) is dead code from the editor era.
- Add a trailing newline to src/Views/home.php.
- Tighten the matchId regex in two tests from {16,} to {16} since
  bin2hex(random_bytes(8)) always produces exactly 16 hex chars; the
  spec's {16,} stays in production TurnToken.

No behavior changes; addresses the deferred-minors parked during
per-task review.
This commit is contained in:
Keith Solomon
2026-07-26 16:38:05 -05:00
parent 3185bc3602
commit 44199ec0a8
5 changed files with 23 additions and 21 deletions
@@ -60,7 +60,7 @@ final class PostMatchActionSmokeTest extends TestCase
$turnToken = $startResponse['body']['turnToken'] ?? null;
self::assertIsArray($match);
self::assertIsString($matchId);
self::assertMatchesRegularExpression('/^[a-f0-9]{16,}$/', $matchId);
self::assertMatchesRegularExpression('/^[a-f0-9]{16}$/', $matchId);
self::assertMatchesRegularExpression('/^[a-f0-9]{32}$/', $turnToken);
for ($i = 0; $i < 200; $i += 1) {