fix(auth): validate invitation magic link tokens - #10651
Conversation
Accept invitation links across configured public origins while still rejecting stored invitations whose token no longer matches.
|
@coderabbitai review |
✅ Action performedReview finished.
|
WalkthroughThis PR refactors the invitation magic-link system to support custom FQDN configuration and strengthen token validation. The hardcoded Come with me if you want to self-host. [Terminator voice] This PR is basically switching from a hardcoded invitation base URL—which is very cloud-function energy, very serverless—to a proper FQDN-aware helper that respects your real infrastructure. Gluten-free servers and taco stands deserve better than magic-link tokens validated by full URL matching. Hash that token the way you hash taco shells. 🌮 ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@tests/Feature/TeamInvitationPrivilegeEscalationTest.php`:
- Around line 188-206: The test currently asserts the invitation link starts
with a hardcoded 'http://localhost' (in the test function using
InstanceSettings, Livewire::test(InviteLink::class) and asserting
$invitation->link) which is environment-coupled; update the assertion to use a
route- or app-url-derived prefix instead (e.g., build the expected prefix with
URL::to('/auth/link?token=') or config('app.url')/route('auth.link') equivalent)
so the assertion compares $invitation->link against the runtime-generated base
URL rather than a fixed localhost string.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 6aee912a-fee1-4e7b-be73-6f5625bc81e6
📒 Files selected for processing (5)
app/Http/Controllers/Controller.phpapp/Livewire/Team/InviteLink.phpconfig/constants.phptests/Feature/InvitationLinkHandlingTest.phptests/Feature/TeamInvitationPrivilegeEscalationTest.php
💤 Files with no reviewable changes (1)
- config/constants.php
Summary
fixes #10633
Fixes #10633