Expose safe production build metadata
This commit is contained in:
@@ -0,0 +1,43 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
namespace App\Http\Controllers;
|
||||
|
||||
use Illuminate\Http\JsonResponse;
|
||||
|
||||
final class BuildInfoController extends Controller
|
||||
{
|
||||
public function __invoke(): JsonResponse
|
||||
{
|
||||
$path = base_path('build-info.json');
|
||||
|
||||
if (! is_file($path) || ! is_readable($path)) {
|
||||
return response()->json(['error' => 'Build info unavailable'], 404)
|
||||
->header('Cache-Control', 'no-store, max-age=0');
|
||||
}
|
||||
|
||||
$decoded = json_decode((string) file_get_contents($path), true);
|
||||
|
||||
if (! is_array($decoded)) {
|
||||
return response()->json(['error' => 'Build info unavailable'], 404)
|
||||
->header('Cache-Control', 'no-store, max-age=0');
|
||||
}
|
||||
|
||||
$commit = trim((string) ($decoded['git_sha'] ?? ''));
|
||||
$release = trim((string) ($decoded['release_id'] ?? ''));
|
||||
$builtAt = trim((string) ($decoded['deployed_at_utc'] ?? ''));
|
||||
|
||||
if ($commit === '' || $release === '' || $builtAt === '') {
|
||||
return response()->json(['error' => 'Build info unavailable'], 404)
|
||||
->header('Cache-Control', 'no-store, max-age=0');
|
||||
}
|
||||
|
||||
return response()->json([
|
||||
'environment' => app()->environment(),
|
||||
'commit' => $commit,
|
||||
'built_at' => $builtAt,
|
||||
'release' => $release,
|
||||
])->header('Cache-Control', 'no-store, max-age=0');
|
||||
}
|
||||
}
|
||||
@@ -1,5 +1,7 @@
|
||||
<?php
|
||||
|
||||
use App\Http\Controllers\BuildInfoController;
|
||||
|
||||
use Illuminate\Support\Facades\Route;
|
||||
use Illuminate\Http\Request;
|
||||
use App\Http\Controllers\User\ProfileController;
|
||||
@@ -78,6 +80,7 @@ use App\Http\Controllers\Settings\CollectionSurfaceController;
|
||||
use App\Services\GroupMembershipService;
|
||||
use Inertia\Inertia;
|
||||
|
||||
Route::get('/build-info.json', BuildInfoController::class)->name('build-info');
|
||||
Route::get('/', [HomeController::class, 'index'])->name('index');
|
||||
Route::get('/home', [HomeController::class, 'index']);
|
||||
// Legacy route compatibility: permanently redirect old lost-password URL to the
|
||||
|
||||
@@ -0,0 +1,47 @@
|
||||
<?php
|
||||
|
||||
use Illuminate\Support\Facades\File;
|
||||
|
||||
it('returns either public build metadata or a non-disclosing not-found response', function (): void {
|
||||
$response = $this->getJson('/build-info.json');
|
||||
|
||||
if (File::exists(base_path('build-info.json'))) {
|
||||
$response->assertOk();
|
||||
expect(array_keys($response->json()))->toBe(['environment', 'commit', 'built_at', 'release']);
|
||||
} else {
|
||||
$response->assertNotFound()
|
||||
->assertJson(['error' => 'Build info unavailable']);
|
||||
}
|
||||
});
|
||||
|
||||
it('exposes only the public release provenance fields', function (): void {
|
||||
$path = base_path('build-info.json');
|
||||
$hadOriginal = File::exists($path);
|
||||
$original = $hadOriginal ? File::get($path) : null;
|
||||
|
||||
File::put($path, json_encode([
|
||||
'git_sha' => 'abc1234',
|
||||
'release_id' => '20260830-b37-abc1234',
|
||||
'deployed_at_utc' => '2026-08-30T09:30:00Z',
|
||||
'git_branch' => 'develop',
|
||||
'git_dirty' => 0,
|
||||
'remote_folder' => '/opt/www/virtual/SkinbaseNova',
|
||||
], JSON_THROW_ON_ERROR));
|
||||
|
||||
try {
|
||||
$this->getJson('/build-info.json')
|
||||
->assertOk()
|
||||
->assertExactJson([
|
||||
'environment' => app()->environment(),
|
||||
'commit' => 'abc1234',
|
||||
'built_at' => '2026-08-30T09:30:00Z',
|
||||
'release' => '20260830-b37-abc1234',
|
||||
]);
|
||||
} finally {
|
||||
if ($hadOriginal) {
|
||||
File::put($path, $original);
|
||||
} else {
|
||||
File::delete($path);
|
||||
}
|
||||
}
|
||||
});
|
||||
Reference in New Issue
Block a user