Expose safe production build metadata

This commit is contained in:
test
2026-08-30 12:16:22 +02:00
parent aba2017273
commit 58e5b3f648
3 changed files with 93 additions and 0 deletions
@@ -0,0 +1,43 @@
<?php
declare(strict_types=1);
namespace App\Http\Controllers;
use Illuminate\Http\JsonResponse;
final class BuildInfoController extends Controller
{
public function __invoke(): JsonResponse
{
$path = base_path('build-info.json');
if (! is_file($path) || ! is_readable($path)) {
return response()->json(['error' => 'Build info unavailable'], 404)
->header('Cache-Control', 'no-store, max-age=0');
}
$decoded = json_decode((string) file_get_contents($path), true);
if (! is_array($decoded)) {
return response()->json(['error' => 'Build info unavailable'], 404)
->header('Cache-Control', 'no-store, max-age=0');
}
$commit = trim((string) ($decoded['git_sha'] ?? ''));
$release = trim((string) ($decoded['release_id'] ?? ''));
$builtAt = trim((string) ($decoded['deployed_at_utc'] ?? ''));
if ($commit === '' || $release === '' || $builtAt === '') {
return response()->json(['error' => 'Build info unavailable'], 404)
->header('Cache-Control', 'no-store, max-age=0');
}
return response()->json([
'environment' => app()->environment(),
'commit' => $commit,
'built_at' => $builtAt,
'release' => $release,
])->header('Cache-Control', 'no-store, max-age=0');
}
}
+3
View File
@@ -1,5 +1,7 @@
<?php
use App\Http\Controllers\BuildInfoController;
use Illuminate\Support\Facades\Route;
use Illuminate\Http\Request;
use App\Http\Controllers\User\ProfileController;
@@ -78,6 +80,7 @@ use App\Http\Controllers\Settings\CollectionSurfaceController;
use App\Services\GroupMembershipService;
use Inertia\Inertia;
Route::get('/build-info.json', BuildInfoController::class)->name('build-info');
Route::get('/', [HomeController::class, 'index'])->name('index');
Route::get('/home', [HomeController::class, 'index']);
// Legacy route compatibility: permanently redirect old lost-password URL to the
+47
View File
@@ -0,0 +1,47 @@
<?php
use Illuminate\Support\Facades\File;
it('returns either public build metadata or a non-disclosing not-found response', function (): void {
$response = $this->getJson('/build-info.json');
if (File::exists(base_path('build-info.json'))) {
$response->assertOk();
expect(array_keys($response->json()))->toBe(['environment', 'commit', 'built_at', 'release']);
} else {
$response->assertNotFound()
->assertJson(['error' => 'Build info unavailable']);
}
});
it('exposes only the public release provenance fields', function (): void {
$path = base_path('build-info.json');
$hadOriginal = File::exists($path);
$original = $hadOriginal ? File::get($path) : null;
File::put($path, json_encode([
'git_sha' => 'abc1234',
'release_id' => '20260830-b37-abc1234',
'deployed_at_utc' => '2026-08-30T09:30:00Z',
'git_branch' => 'develop',
'git_dirty' => 0,
'remote_folder' => '/opt/www/virtual/SkinbaseNova',
], JSON_THROW_ON_ERROR));
try {
$this->getJson('/build-info.json')
->assertOk()
->assertExactJson([
'environment' => app()->environment(),
'commit' => 'abc1234',
'built_at' => '2026-08-30T09:30:00Z',
'release' => '20260830-b37-abc1234',
]);
} finally {
if ($hadOriginal) {
File::put($path, $original);
} else {
File::delete($path);
}
}
});