fix: reject non-UUID auth identifiers from stale sessions before API calls
This commit is contained in:
@@ -46,9 +46,13 @@ class InsForgeAuthService
|
|||||||
return $this->hydrateProfile($profile);
|
return $this->hydrateProfile($profile);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private const UUID_PATTERN = '/^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$/i';
|
||||||
|
|
||||||
public function profileById(?string $id): ?User
|
public function profileById(?string $id): ?User
|
||||||
{
|
{
|
||||||
if ($id === null) {
|
// Sesi lama bisa menyimpan identifier non-UUID (mis. "1") — jangan sampai
|
||||||
|
// mengirim nilai itu ke PostgREST; anggap tidak dikenal dan paksa login ulang.
|
||||||
|
if (! is_string($id) || preg_match(self::UUID_PATTERN, $id) !== 1) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,2 +0,0 @@
|
|||||||
*
|
|
||||||
!.gitignore
|
|
||||||
Reference in New Issue
Block a user