Expose safe production build metadata
This commit is contained in:
@@ -0,0 +1,43 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
declare(strict_types=1);
|
||||||
|
|
||||||
|
namespace App\Http\Controllers;
|
||||||
|
|
||||||
|
use Illuminate\Http\JsonResponse;
|
||||||
|
|
||||||
|
final class BuildInfoController extends Controller
|
||||||
|
{
|
||||||
|
public function __invoke(): JsonResponse
|
||||||
|
{
|
||||||
|
$path = base_path('build-info.json');
|
||||||
|
|
||||||
|
if (! is_file($path) || ! is_readable($path)) {
|
||||||
|
return response()->json(['error' => 'Build info unavailable'], 404)
|
||||||
|
->header('Cache-Control', 'no-store, max-age=0');
|
||||||
|
}
|
||||||
|
|
||||||
|
$decoded = json_decode((string) file_get_contents($path), true);
|
||||||
|
|
||||||
|
if (! is_array($decoded)) {
|
||||||
|
return response()->json(['error' => 'Build info unavailable'], 404)
|
||||||
|
->header('Cache-Control', 'no-store, max-age=0');
|
||||||
|
}
|
||||||
|
|
||||||
|
$commit = trim((string) ($decoded['git_sha'] ?? ''));
|
||||||
|
$release = trim((string) ($decoded['release_id'] ?? ''));
|
||||||
|
$builtAt = trim((string) ($decoded['deployed_at_utc'] ?? ''));
|
||||||
|
|
||||||
|
if ($commit === '' || $release === '' || $builtAt === '') {
|
||||||
|
return response()->json(['error' => 'Build info unavailable'], 404)
|
||||||
|
->header('Cache-Control', 'no-store, max-age=0');
|
||||||
|
}
|
||||||
|
|
||||||
|
return response()->json([
|
||||||
|
'environment' => app()->environment(),
|
||||||
|
'commit' => $commit,
|
||||||
|
'built_at' => $builtAt,
|
||||||
|
'release' => $release,
|
||||||
|
])->header('Cache-Control', 'no-store, max-age=0');
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,5 +1,7 @@
|
|||||||
<?php
|
<?php
|
||||||
|
|
||||||
|
use App\Http\Controllers\BuildInfoController;
|
||||||
|
|
||||||
use Illuminate\Support\Facades\Route;
|
use Illuminate\Support\Facades\Route;
|
||||||
use Illuminate\Http\Request;
|
use Illuminate\Http\Request;
|
||||||
use App\Http\Controllers\User\ProfileController;
|
use App\Http\Controllers\User\ProfileController;
|
||||||
@@ -78,6 +80,7 @@ use App\Http\Controllers\Settings\CollectionSurfaceController;
|
|||||||
use App\Services\GroupMembershipService;
|
use App\Services\GroupMembershipService;
|
||||||
use Inertia\Inertia;
|
use Inertia\Inertia;
|
||||||
|
|
||||||
|
Route::get('/build-info.json', BuildInfoController::class)->name('build-info');
|
||||||
Route::get('/', [HomeController::class, 'index'])->name('index');
|
Route::get('/', [HomeController::class, 'index'])->name('index');
|
||||||
Route::get('/home', [HomeController::class, 'index']);
|
Route::get('/home', [HomeController::class, 'index']);
|
||||||
// Legacy route compatibility: permanently redirect old lost-password URL to the
|
// Legacy route compatibility: permanently redirect old lost-password URL to the
|
||||||
|
|||||||
@@ -0,0 +1,47 @@
|
|||||||
|
<?php
|
||||||
|
|
||||||
|
use Illuminate\Support\Facades\File;
|
||||||
|
|
||||||
|
it('returns either public build metadata or a non-disclosing not-found response', function (): void {
|
||||||
|
$response = $this->getJson('/build-info.json');
|
||||||
|
|
||||||
|
if (File::exists(base_path('build-info.json'))) {
|
||||||
|
$response->assertOk();
|
||||||
|
expect(array_keys($response->json()))->toBe(['environment', 'commit', 'built_at', 'release']);
|
||||||
|
} else {
|
||||||
|
$response->assertNotFound()
|
||||||
|
->assertJson(['error' => 'Build info unavailable']);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
it('exposes only the public release provenance fields', function (): void {
|
||||||
|
$path = base_path('build-info.json');
|
||||||
|
$hadOriginal = File::exists($path);
|
||||||
|
$original = $hadOriginal ? File::get($path) : null;
|
||||||
|
|
||||||
|
File::put($path, json_encode([
|
||||||
|
'git_sha' => 'abc1234',
|
||||||
|
'release_id' => '20260830-b37-abc1234',
|
||||||
|
'deployed_at_utc' => '2026-08-30T09:30:00Z',
|
||||||
|
'git_branch' => 'develop',
|
||||||
|
'git_dirty' => 0,
|
||||||
|
'remote_folder' => '/opt/www/virtual/SkinbaseNova',
|
||||||
|
], JSON_THROW_ON_ERROR));
|
||||||
|
|
||||||
|
try {
|
||||||
|
$this->getJson('/build-info.json')
|
||||||
|
->assertOk()
|
||||||
|
->assertExactJson([
|
||||||
|
'environment' => app()->environment(),
|
||||||
|
'commit' => 'abc1234',
|
||||||
|
'built_at' => '2026-08-30T09:30:00Z',
|
||||||
|
'release' => '20260830-b37-abc1234',
|
||||||
|
]);
|
||||||
|
} finally {
|
||||||
|
if ($hadOriginal) {
|
||||||
|
File::put($path, $original);
|
||||||
|
} else {
|
||||||
|
File::delete($path);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
Reference in New Issue
Block a user