fix: reject non-UUID auth identifiers from stale sessions before API calls

This commit is contained in:
sean
2026-08-25 19:34:51 +07:00
parent feba1ec839
commit 14614548d9
2 changed files with 5 additions and 3 deletions
@@ -46,9 +46,13 @@ class InsForgeAuthService
return $this->hydrateProfile($profile); return $this->hydrateProfile($profile);
} }
private const UUID_PATTERN = '/^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$/i';
public function profileById(?string $id): ?User public function profileById(?string $id): ?User
{ {
if ($id === null) { // Sesi lama bisa menyimpan identifier non-UUID (mis. "1") — jangan sampai
// mengirim nilai itu ke PostgREST; anggap tidak dikenal dan paksa login ulang.
if (! is_string($id) || preg_match(self::UUID_PATTERN, $id) !== 1) {
return null; return null;
} }
-2
View File
@@ -1,2 +0,0 @@
*
!.gitignore