Editor image upload: optional ability check, 10 MB limit, tests and changelog
Closes #37
Context
Most of #37 was already merged to main with !13 (merged) (not released yet, not in v1.0.85): route inside configurable middleware (['web', 'auth']), validation, random file names, 422 JSON errors, rate limit. This MR closes the remaining gaps to the acceptance criteria.
Changes
- Ability:
editor_image_upload_abilitynow defaults tonull(any authenticated user). If set, the controller returns403whenGate::denies()the ability. TheAuthorizeEditorImageUploadmiddleware from !13 (merged) is removed: it only checked abilities registered viaGate::define()(Gate::has()), so abilities resolved viaGate::before()(e.g. spatie/laravel-permission) or a typo silently allowed every user. The check now fails closed. - Size limit:
editor_image_upload_max_sizedefault 8192 → 10240 KB. - Tests (
tests/EditorImageUploadTest.php): missing CSRF token → 419; token accepted asX-CSRF-TOKENheader and as?_token=(what the CK editor sends); svg, html, php and html/php with an image extension and image MIME type → 422, nothing stored (the content check was verified by a mutation: a name-onlyextensions:rule fails these cases); real image stored, URL returned; ability configured and denied/undefined → 403. Session and cache stores are pinned toarray, so the tests also pass undertestbench package:test(onmain8 of them failed there withno such table: cache). - Docs: new
CHANGELOG.md(1.1.0) and README section updated with all config keys and the breaking change.
Deviations from the task
- CK editor CSRF: unchanged. The component already sends the token as
?_token=in the upload URL, which Laravel's CSRF middleware accepts (covered by a test). AnX-CSRF-TOKENheader is not possible with the bundled CKEditor 5.37.1 super-build: itsCKFinderUploadAdapterhas no header option, andSimpleUploadAdapteris not part of that build (checked in the CDN bundle). A custom JS upload adapter would be needed for that, which I did not add. - Trix: no change. The Trix component uploads through Livewire (
@this.upload,WithEditorFileUploads), not through this route; Livewire sends its own CSRF token. - Config keys from !13 (merged) (
_enabled,_rate_limit,_mimes,_path) are kept.
Breaking change
Guests can no longer upload editor images; the route needs a logged-in user and a valid CSRF token. Apps that published the config file must add the new keys or remove them from the published file to use the defaults. After the release every consumer app needs composer update berlin-bird-studios/blade-components and a deploy.
Release
!14 (merged) (Livewire 3/4 migration) is planned as 1.1.0. I recommend shipping both together as 1.1.0. Both MRs add CHANGELOG.md with a ## 1.1.0 section, so whichever merges second has a small conflict there: keep the ### Changed entries of !14 (merged) and the ### Security entry of this MR (the !14 (merged) line still mentions the edit-text default, which no longer applies).
Tests
vendor/bin/paratest and vendor/bin/testbench package:test --parallel both green on f53f0753 (20 tests, 57 assertions; the only notice is the existing deprecated phpunit.xml schema).
Not merged, not tagged.
Prepared by BBS Copilot