3185bc3602c65b30bb589ff7ce215375c612f638
CI / php (push) Failing after 1m17s
When a browser session predates a server restart with a fresh secret.key, the old __csrf HMAC cookie is no longer verifiable under the new secret. Every action POST returns 403 until the user manually clears cookies, because the existing-pair check on the front controller was 'is the cookie present?' rather than 'does the cookie verify under the current secret?'. The new check at the top of the front controller computes the expected HMAC of the raw-token cookie under the current secret and constant-time-compares it to the __csrf cookie. If they don't match, the controller re-mints a fresh pair on the response, replacing the browser's stale cookies with a working set. The next click of 'Play bundled' then succeeds without user intervention. Test coverage in tests/Integration/StaleCookieRotationTest.php: - testStaleCookiesAreReplacedOnNextRequest - testValidCookiesAreNotReIssuedOnNextRequest - testMissingTokenCookieIsFilledInOnNextRequest
Description
No description provided
535 KiB