Skip to content

#115 Users: generate the API token with a POST request and a CSRF token - #116

Draft
njoubert-cleverage wants to merge 1 commit into
mainfrom
115
Draft

njoubert-cleverage wants to merge 1 commit into
mainfrom
115

Conversation

@njoubert-cleverage

Copy link
Copy Markdown
Member

Description

Fixes #115. Milestone v4.0 (BC break, see below).

UserCrudController:

  • "generateToken" action (edit page): URL built with a CSRF token per user (linkToUrl(), csrfToken query parameter), rendered as a POST form (renderAsForm()) with a confirmation (askConfirmation(): "The current API token of this user will no longer work.")
  • #[AdminRoute] restricted to POST (GET: 405); the CSRF token is checked (403 otherwise)
  • token generated with bin2hex(random_bytes(16)) (32 hexadecimal characters, as before) instead of md5(uniqid(date('YmdHis')))

Docs: UPGRADE.md v4.0, CHANGELOG under BC break.

Tests:

  • UserCrudTest::testGenerateTokenRequiresAPostRequestWithACsrfToken: GET → 405, POST without / with an invalid CSRF token → 403, token unchanged
  • UserCrudTest::testGenerateToken, HttpProcessExecuteTest::testTokenGeneratedInTheUi: the token is generated by submitting the form of the edit page (FunctionalTestCase::generateTokenInTheUi()), then used on the API

Checked:

  • bundle (Symfony 8.1, PHP 8.5): 267 tests OK; without the fix, the 3 tests fail. PHPStan, PHP-CS-Fixer, Rector OK
  • process-bundle-demo (Symfony 7.4, EasyAdmin 5.6): GET → 405, POST without CSRF → 403 (token unchanged); POST form of the edit page (with the EasyAdmin confirmation modal) → new 32 characters token, accepted by the HTTP API

Note: UPGRADE.md and the CHANGELOG BC break section are also added by #94 (milestone v4.0): the second merged PR will need a rebase.

Requirements

  • Documentation updates
    • Reference
    • Changelog
  • Unit tests

Breaking changes

The direct GET /process/user/{id}/generate-token URL no longer works (405): the token is generated from the button of the user edit page (see UPGRADE.md v4.0).

🤖 Generated with Claude Code

The "generateToken" action was a link: a simple GET request (forged link, image…) replaced the API token of a user.
It is now a POST form with a CSRF token per user and a confirmation; the route only accepts POST. The token is
generated with random_bytes() (was md5(uniqid(date()))). BC break for the direct GET URL, see UPGRADE.md v4.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@njoubert-cleverage njoubert-cleverage added this to the v4.0 milestone Oct 7, 2026
@njoubert-cleverage njoubert-cleverage added the enhancement New feature or request label Oct 7, 2026
@njoubert-cleverage
njoubert-cleverage marked this pull request as draft October 8, 2026 09:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Users: API token replaced by a simple GET request (no CSRF token)

1 participant