Suppress expected OAuth access denial reports

This commit is contained in:
Constantin Graf
2026-08-31 11:39:30 +02:00
parent ba778bdddf
commit 0d1d9a4ee7
3 changed files with 59 additions and 2 deletions

View File

@@ -7,6 +7,7 @@ namespace App\Exceptions;
use Illuminate\Foundation\Exceptions\Handler as ExceptionHandler;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use League\OAuth2\Server\Exception\OAuthServerException;
use Symfony\Component\HttpFoundation\Exception\SuspiciousOperationException;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\HttpKernel\Exception\BadRequestHttpException;
@@ -34,6 +35,10 @@ class Handler extends ExceptionHandler
//
});
$this->dontReportWhen(fn (Throwable $e): bool => $e instanceof OAuthServerException
&& $e->getErrorType() === 'access_denied'
&& $e->getHttpStatusCode() === 401);
// A request on an untrusted host (see App\Http\Middleware\TrustHosts)
// otherwise renders as a bare "Bad request." 400. Show a message that
// says how to fix it instead. The framework has already converted the

View File

@@ -63,7 +63,13 @@ class ApiExceptionTest extends TestCase
#[DataProvider('expectedApiExceptionProvider')]
public function test_expected_api_exceptions_are_not_reported(ApiException $exception): void
{
$this->assertTrue($exception->report());
// Arrange: exception supplied by the data provider
// Act
$reportingHandled = $exception->report();
// Assert
$this->assertTrue($reportingHandled);
}
/**
@@ -79,6 +85,12 @@ class ApiExceptionTest extends TestCase
#[DataProvider('operationalApiExceptionProvider')]
public function test_operational_api_exceptions_are_reported(ApiException $exception): void
{
$this->assertFalse($exception->report());
// Arrange: exception supplied by the data provider
// Act
$reportingHandled = $exception->report();
// Assert
$this->assertFalse($reportingHandled);
}
}

View File

@@ -0,0 +1,40 @@
<?php
declare(strict_types=1);
namespace Tests\Unit\Exceptions;
use App\Exceptions\Handler;
use League\OAuth2\Server\Exception\OAuthServerException;
use RuntimeException;
use Tests\TestCase;
class HandlerTest extends TestCase
{
public function test_oauth_access_denied_exceptions_are_not_reported(): void
{
// Arrange
$exception = OAuthServerException::accessDenied(
'Access token could not be verified',
previous: new RuntimeException('The token is expired')
);
// Act
$shouldReport = app(Handler::class)->shouldReport($exception);
// Assert
$this->assertFalse($shouldReport);
}
public function test_operational_oauth_exceptions_are_reported(): void
{
// Arrange
$exception = OAuthServerException::serverError('Signing key could not be read');
// Act
$shouldReport = app(Handler::class)->shouldReport($exception);
// Assert
$this->assertTrue($shouldReport);
}
}