Skip to content

fix(auth): validate invitation magic link tokens - #10651

Merged
andrasbacsai merged 6 commits into
nextfrom
10633-invitation-link-redirect
Jul 3, 2026
Merged

andrasbacsai merged 6 commits into
nextfrom
10633-invitation-link-redirect

Conversation

@andrasbacsai

Copy link
Copy Markdown
Member

Summary

  • Generate invitation URLs from named routes and honor the configured instance FQDN for new-user magic links.
  • Validate invitation magic links by matching the token stored on the invitation instead of comparing the full request URL, so links work across public origins.
  • Add coverage for cross-origin invitation acceptance, token mismatch rejection, and FQDN-based link generation.

fixes #10633


Fixes #10633

Accept invitation links across configured public origins while still
rejecting stored invitations whose token no longer matches.
@andrasbacsai

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 12, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Walkthrough

This PR refactors the invitation magic-link system to support custom FQDN configuration and strengthen token validation. The hardcoded /invitations/ base URL is removed from config, replaced by a centralized invitationUrl() helper in the InviteLink component that respects the configured instance FQDN and falls back to route URLs. The token validation logic in Controller::link() is tightened to require a non-empty token string and now validates by comparing the request token against the token stored in the invitation's link query parameters using hash_equals, removing prior full-URL matching. Four new feature tests verify correct behavior: FQDN-aware URL generation, magic-link acceptance across origins, token mismatch rejection, and localhost route fallback when FQDN is unconfigured.


Come with me if you want to self-host. [Terminator voice] This PR is basically switching from a hardcoded invitation base URL—which is very cloud-function energy, very serverless—to a proper FQDN-aware helper that respects your real infrastructure. Gluten-free servers and taco stands deserve better than magic-link tokens validated by full URL matching. Hash that token the way you hash taco shells. 🌮

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch 10633-invitation-link-redirect

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/Feature/TeamInvitationPrivilegeEscalationTest.php`:
- Around line 188-206: The test currently asserts the invitation link starts
with a hardcoded 'http://localhost' (in the test function using
InstanceSettings, Livewire::test(InviteLink::class) and asserting
$invitation->link) which is environment-coupled; update the assertion to use a
route- or app-url-derived prefix instead (e.g., build the expected prefix with
URL::to('/auth/link?token=') or config('app.url')/route('auth.link') equivalent)
so the assertion compares $invitation->link against the runtime-generated base
URL rather than a fixed localhost string.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 6aee912a-fee1-4e7b-be73-6f5625bc81e6

📥 Commits

Reviewing files that changed from the base of the PR and between 442ed98 and 4f509c0.

📒 Files selected for processing (5)
  • app/Http/Controllers/Controller.php
  • app/Livewire/Team/InviteLink.php
  • config/constants.php
  • tests/Feature/InvitationLinkHandlingTest.php
  • tests/Feature/TeamInvitationPrivilegeEscalationTest.php
💤 Files with no reviewable changes (1)
  • config/constants.php

Comment thread tests/Feature/Team/TeamInvitationPrivilegeEscalationTest.php
@andrasbacsai
andrasbacsai merged commit bf37db3 into next Jul 3, 2026
3 checks passed
@andrasbacsai
andrasbacsai deleted the 10633-invitation-link-redirect branch July 3, 2026 07:38
@andrasbacsai andrasbacsai mentioned this pull request Jul 14, 2026
@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Aug 14, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant