feat(web-api): customer logout and password recovery routes#442
Open
Ibochkarev wants to merge 5 commits into
Open
feat(web-api): customer logout and password recovery routes#442Ibochkarev wants to merge 5 commits into
Ibochkarev wants to merge 5 commits into
Conversation
Wire existing Logout, ForgotPassword, and ResetPassword processors into the public Web API via CustomerAuthController. Logout runs behind TokenMiddleware so MS3TOKEN populates session before revocation; forgot- password rate limits return HTTP 429 through processor failure codes. Closes #422
Limit password reset attempts to 5 per 15 minutes per IP and per reset token, returning HTTP 429 via processor failure code. Clears counters on successful reset to match login bruteforce protection. Refs #422
Move JSON body parsing into CustomerAuthController *FromRequest methods so web.php closures only delegate. Replace grep-based CustomerAuthRoutesTest with Router introspection for middleware and handler delegation. Refs #422
Reuse one closure factory per /customer group instead of five inline CustomerAuthController instantiations. Test verifies factory via reflection. Refs #422
Add CustomerAuthEndpointsTest with controller mapping checks, router dispatch for logout (TokenMiddleware + session), and stdin-piped dispatch for forgot/reset-password. WebApiModxStub mocks runProcessor without MODX. Refs #422
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Описание
Публичный Web API не экспонировал процессоры logout / forgot-password / reset-password — headless-клиент не мог завершить сессию и восстановить пароль без connector.
Добавлен
CustomerAuthController(login, register, logout, forgotPassword, resetPassword) и три новых маршрута. Login/register переведены на тот же контроллер вместо inlinerunProcessor. Logout идёт черезTokenMiddleware, чтобы MS3TOKEN/cookie заполнили$_SESSIONдо отзыва токенов. Rate limit forgot-password отдаёт HTTP 429 через['code' => HttpStatus::TOO_MANY_REQUESTS]в процессоре.Тип изменений
Связанные Issues
Closes #422
Как это было протестировано?
Конфигурация тестирования:
Скриншоты (если применимо)
n/a
Чеклист
Дополнительные заметки
POST /api/v1/customer/logout,/forgot-password,/reset-password.