From a2270364a6d627aa38bac6ea7f4004daa086e3f5 Mon Sep 17 00:00:00 2001 From: Andre Klapper Date: Fri, 2 Jan 2026 23:25:14 +0100 Subject: [PATCH] Conduit: Add error handling calling token.give without objectPHID Summary: Throw a ConduitException when no objectPHID is passed instead of silently failing when trying to delete a token being `null`. As a side effect, fix a PHP 8.5 deprecation warning. Closes T16436 Test Plan: Go to http://phorge.localhost/conduit/method/token.give/ and press "Call Method". Try also after entering a random string in the "tokenPHID" field. Reviewers: O1 Blessed Committers, mainframe98 Reviewed By: O1 Blessed Committers, mainframe98 Subscribers: mainframe98, tobiaswiese, valerio.bozzolan, Matthew, Cigaryno Maniphest Tasks: T16436 Differential Revision: https://we.phorge.it/D26647 --- .../conduit/TokenGiveConduitAPIMethod.php | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/src/applications/tokens/conduit/TokenGiveConduitAPIMethod.php b/src/applications/tokens/conduit/TokenGiveConduitAPIMethod.php index eb591025b2..31b185931b 100644 --- a/src/applications/tokens/conduit/TokenGiveConduitAPIMethod.php +++ b/src/applications/tokens/conduit/TokenGiveConduitAPIMethod.php @@ -21,8 +21,21 @@ final class TokenGiveConduitAPIMethod extends TokenConduitAPIMethod { return 'void'; } + protected function defineErrorTypes() { + return array( + 'ERR-BAD-PHID' => pht( + 'Must pass a PHID for parameter "%s".', + 'objectPHID'), + ); + } + protected function execute(ConduitAPIRequest $request) { $content_source = $request->newContentSource(); + $phid = $request->getValue('objectPHID'); + + if ($phid === null) { + throw new ConduitException('ERR-BAD-PHID'); + } $editor = id(new PhabricatorTokenGivenEditor()) ->setActor($request->getUser()) @@ -30,10 +43,10 @@ final class TokenGiveConduitAPIMethod extends TokenConduitAPIMethod { if ($request->getValue('tokenPHID')) { $editor->addToken( - $request->getValue('objectPHID'), + $phid, $request->getValue('tokenPHID')); } else { - $editor->deleteToken($request->getValue('objectPHID')); + $editor->deleteToken($phid); } } -- 2.51.2