[FIX] Auth CRITICI da test multi-agente: register senza jti + revoca sessione singola

CRITICO #2 — register() generava il token SENZA jti, ma requireAuth lo rifiuta
(JWT_NO_JTI): l'utente appena registrato veniva sbattuto fuori al primo
getMe/completeOnboarding e doveva rifare login. Ora register crea una riga
active_sessions con jti e genera access+refresh token col jti, come login().

CRITICO #1 — DELETE /auth/sessions/<jti> (revoca sessione singola) tornava 404:
il jti è esadecimale (non numerico), il router cadeva nel ramo "nome composto"
e generava solo {action}/{camelResource}, mai {action}/{id}. Aggiunto fallback
{action}/{id} con id passato come STRINGA (revokeSession(string $id) lo accetta).
Il candidato composito resta primo, quindi evidence/upload ecc. non si rompono.

php -l OK su entrambi. version 1.10.4.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
DevEnv nis2-agile
2026-05-31 15:01:22 +02:00
co-authored by Claude Opus 4.8
parent 2037cecaba
commit c134a2d52a
3 changed files with 24 additions and 4 deletions
+19 -3
View File
@@ -91,9 +91,25 @@ class AuthController extends BaseController
'is_active' => 1,
]);
// Genera tokens
$accessToken = $this->generateJWT($userId);
$refreshToken = $this->generateRefreshToken($userId);
// --- Sessione tracciata (jti) come nel login: requireAuth rifiuta i token
// senza jti, quindi senza questo l'utente appena registrato verrebbe
// sbattuto fuori al primo getMe/completeOnboarding (401 JWT_NO_JTI). ---
$jti = bin2hex(random_bytes(16));
$ua = $_SERVER['HTTP_USER_AGENT'] ?? '';
$ip = $this->getClientIP();
Database::insert('active_sessions', [
'id' => $jti,
'user_id' => (int) $userId,
'organization_id' => null,
'ip_address' => $ip,
'user_agent' => substr($ua, 0, 512),
'device_label' => $this->parseDeviceLabel($ua),
'expires_at' => date('Y-m-d H:i:s', time() + JWT_REFRESH_EXPIRES_IN),
]);
// Genera tokens (con jti, come login)
$accessToken = $this->generateJWT($userId, ['jti' => $jti]);
$refreshToken = $this->generateRefreshToken($userId, $jti);
// Audit log
$this->currentUser = ['id' => $userId];