Editor image upload: optional ability check, 10 MB limit, tests and changelog

Closes #37

Context

Most of #37 was already merged to main with !13 (merged) (not released yet, not in v1.0.85): route inside configurable middleware (['web', 'auth']), validation, random file names, 422 JSON errors, rate limit. This MR closes the remaining gaps to the acceptance criteria.

Changes

  • Ability: editor_image_upload_ability now defaults to null (any authenticated user). If set, the controller returns 403 when Gate::denies() the ability. The AuthorizeEditorImageUpload middleware from !13 (merged) is removed: it only checked abilities registered via Gate::define() (Gate::has()), so abilities resolved via Gate::before() (e.g. spatie/laravel-permission) or a typo silently allowed every user. The check now fails closed.
  • Size limit: editor_image_upload_max_size default 8192 → 10240 KB.
  • Tests (tests/EditorImageUploadTest.php): missing CSRF token → 419; token accepted as X-CSRF-TOKEN header and as ?_token= (what the CK editor sends); svg, html, php and html/php with an image extension and image MIME type → 422, nothing stored (the content check was verified by a mutation: a name-only extensions: rule fails these cases); real image stored, URL returned; ability configured and denied/undefined → 403. Session and cache stores are pinned to array, so the tests also pass under testbench package:test (on main 8 of them failed there with no such table: cache).
  • Docs: new CHANGELOG.md (1.1.0) and README section updated with all config keys and the breaking change.

Deviations from the task

  • CK editor CSRF: unchanged. The component already sends the token as ?_token= in the upload URL, which Laravel's CSRF middleware accepts (covered by a test). An X-CSRF-TOKEN header is not possible with the bundled CKEditor 5.37.1 super-build: its CKFinderUploadAdapter has no header option, and SimpleUploadAdapter is not part of that build (checked in the CDN bundle). A custom JS upload adapter would be needed for that, which I did not add.
  • Trix: no change. The Trix component uploads through Livewire (@this.upload, WithEditorFileUploads), not through this route; Livewire sends its own CSRF token.
  • Config keys from !13 (merged) (_enabled, _rate_limit, _mimes, _path) are kept.

Breaking change

Guests can no longer upload editor images; the route needs a logged-in user and a valid CSRF token. Apps that published the config file must add the new keys or remove them from the published file to use the defaults. After the release every consumer app needs composer update berlin-bird-studios/blade-components and a deploy.

Release

!14 (merged) (Livewire 3/4 migration) is planned as 1.1.0. I recommend shipping both together as 1.1.0. Both MRs add CHANGELOG.md with a ## 1.1.0 section, so whichever merges second has a small conflict there: keep the ### Changed entries of !14 (merged) and the ### Security entry of this MR (the !14 (merged) line still mentions the edit-text default, which no longer applies).

Tests

vendor/bin/paratest and vendor/bin/testbench package:test --parallel both green on f53f0753 (20 tests, 57 assertions; the only notice is the existing deprecated phpunit.xml schema).

Not merged, not tagged.

Prepared by BBS Copilot

Merge request reports

Loading
Loading