From 0d1d9a4ee7e62c795989e01528a719f60f395347 Mon Sep 17 00:00:00 2001 From: Constantin Graf Date: Mon, 31 Aug 2026 11:39:30 +0200 Subject: [PATCH] Suppress expected OAuth access denial reports --- app/Exceptions/Handler.php | 5 +++ .../Unit/Exceptions/Api/ApiExceptionTest.php | 16 +++++++- tests/Unit/Exceptions/HandlerTest.php | 40 +++++++++++++++++++ 3 files changed, 59 insertions(+), 2 deletions(-) create mode 100644 tests/Unit/Exceptions/HandlerTest.php diff --git a/app/Exceptions/Handler.php b/app/Exceptions/Handler.php index fad5f597..f1636d46 100644 --- a/app/Exceptions/Handler.php +++ b/app/Exceptions/Handler.php @@ -7,6 +7,7 @@ namespace App\Exceptions; use Illuminate\Foundation\Exceptions\Handler as ExceptionHandler; use Illuminate\Http\RedirectResponse; use Illuminate\Http\Request; +use League\OAuth2\Server\Exception\OAuthServerException; use Symfony\Component\HttpFoundation\Exception\SuspiciousOperationException; use Symfony\Component\HttpFoundation\Response; use Symfony\Component\HttpKernel\Exception\BadRequestHttpException; @@ -34,6 +35,10 @@ class Handler extends ExceptionHandler // }); + $this->dontReportWhen(fn (Throwable $e): bool => $e instanceof OAuthServerException + && $e->getErrorType() === 'access_denied' + && $e->getHttpStatusCode() === 401); + // A request on an untrusted host (see App\Http\Middleware\TrustHosts) // otherwise renders as a bare "Bad request." 400. Show a message that // says how to fix it instead. The framework has already converted the diff --git a/tests/Unit/Exceptions/Api/ApiExceptionTest.php b/tests/Unit/Exceptions/Api/ApiExceptionTest.php index 7fca6d79..e52bff0d 100644 --- a/tests/Unit/Exceptions/Api/ApiExceptionTest.php +++ b/tests/Unit/Exceptions/Api/ApiExceptionTest.php @@ -63,7 +63,13 @@ class ApiExceptionTest extends TestCase #[DataProvider('expectedApiExceptionProvider')] public function test_expected_api_exceptions_are_not_reported(ApiException $exception): void { - $this->assertTrue($exception->report()); + // Arrange: exception supplied by the data provider + + // Act + $reportingHandled = $exception->report(); + + // Assert + $this->assertTrue($reportingHandled); } /** @@ -79,6 +85,12 @@ class ApiExceptionTest extends TestCase #[DataProvider('operationalApiExceptionProvider')] public function test_operational_api_exceptions_are_reported(ApiException $exception): void { - $this->assertFalse($exception->report()); + // Arrange: exception supplied by the data provider + + // Act + $reportingHandled = $exception->report(); + + // Assert + $this->assertFalse($reportingHandled); } } diff --git a/tests/Unit/Exceptions/HandlerTest.php b/tests/Unit/Exceptions/HandlerTest.php new file mode 100644 index 00000000..ec808995 --- /dev/null +++ b/tests/Unit/Exceptions/HandlerTest.php @@ -0,0 +1,40 @@ +shouldReport($exception); + + // Assert + $this->assertFalse($shouldReport); + } + + public function test_operational_oauth_exceptions_are_reported(): void + { + // Arrange + $exception = OAuthServerException::serverError('Signing key could not be read'); + + // Act + $shouldReport = app(Handler::class)->shouldReport($exception); + + // Assert + $this->assertTrue($shouldReport); + } +}