Repository navigation
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
- EC-CUBE 4.4 が同梱する robthree/twofactorauth v3 はコンストラクタの第 1 引数 (IQRCodeProvider) が必須で、引数なしでは初回登録・認証画面が 500 になる - 本体の TwoFactorAuthService と同じ QRServerProvider を渡す。QR コードは画面側の jquery.qrcode で描画しており、プロバイダは使われない Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ttokoro20240902
left a comment
There was a problem hiding this comment.
修正をお願いします。
- PR 本文の「秘密鍵が欠落した場合、鍵を再発行して入力画面を出し直すフォールバックを追加」に当たる実装が見当たりません。現状はセッションに鍵が無いと
is_string($auth_key)が false になり、エラー表示のうえauth_keyが null のまま QR を描画します。実装するか、本文とテスト欄の記載を外してください。 removePages()の条件修正(!$Page→$Page !== null)で、無効化・アンインストール時に dtb_page が実際に削除されるようになりました。この挙動を確かめるテストを追加してください。
| path: 'TwoFactorAuthCustomer42' | ||
| # 親プラグイン PR が公式 4.4 にマージされるまで、パッケージ名 twofactorauthcustomer44 が入っている | ||
| # KenTanaka/TwoFactorAuthCustomer の feat-4.4 を参照する。マージ後は EC-CUBE/TwoFactorAuthCustomer42@4.4 に戻す。 | ||
| repository: 'KenTanaka/TwoFactorAuthCustomer' |
There was a problem hiding this comment.
親プラグインを個人 fork KenTanaka/TwoFactorAuthCustomer@feat-4.4 から取得しています。公式リポジトリの CI が個人リポジトリに依存しないよう、EC-CUBE/TwoFactorAuthCustomer42#59 のマージ後に EC-CUBE/TwoFactorAuthCustomer42 の 4.4 へ戻してからマージしてください(L232 の static-analysis も同様)。
| * @return array<string, mixed>|RedirectResponse | ||
| */ | ||
| #[Route(path: '/mypage/two_factor_auth/app/create', name: 'plg_customer_2fa_app_create', methods: ['GET', 'POST'])] | ||
| #[Template('@TwoFactorAuthCustomerApp44/default/tfa/app/register.twig')] |
There was a problem hiding this comment.
@TwoFactorAuthCustomerApp44/... 形式にしたため、テンプレートが app/template/plugin/{code} → プラグインの Resource/template の順で解決され、app/template/{theme} は見なくなります。その結果、copyTwigFiles() が配置するコピーと、ページ管理での編集が画面に反映されません。TwoFactorAuthCustomerApp44/Resource/template/default/... のパス形式で指定してください(L112 も同様)。詳細は EC-CUBE/TwoFactorAuthCustomer42#59 を参照してください。
概要
会員向けアプリ認証(TOTP)プラグインを EC-CUBE 4.4(Symfony 7.4 / Doctrine ORM 3.0 / PHP 8.2+) に対応させ、コードを
TwoFactorAuthCustomerApp42→TwoFactorAuthCustomerApp44に改名します。親プラグイン依存もTwoFactorAuthCustomer42→TwoFactorAuthCustomer44に更新します。4.3 とは非互換(属性必須・ORM 3・PHP 8.2+)のため、新規4.4ブランチへの取り込みです。参考: 4.3→4.4 マイグレーション手順 (doc #346) /
変更内容
1. EC-CUBE 4.4 対応(コア移行)
@Route/@Template→#[Route]/#[Template](Sensio依存除去)、EntityExtension の@EntityExtension→#[EntityExtension](Eccube\Attribute\EntityExtension)Types::STRING)、メソッド引数・戻り値型(createSecret(): string/verifyCode(...): bool等)enable/disable/uninstallほか関連メソッドに: void@TwoFactorAuthCustomerApp44/...およびページ登録パスをTwoFactorAuthCustomerApp44に統一requireをec-cube/twofactorauthcustomer44へ、code/version: 4.4.0をTwoFactorAuthCustomerApp44に統一phpunit.xml.distを<source>/<extensions>形式へ、Tests/bootstrap.phpを追加2. 動作改善(初回APP認証)
/mypage/two_factor_auth/app/create)でセッション切れ等により秘密鍵が欠落した場合、鍵を再発行して入力画面を出し直すフォールバックを追加verifyCodeを実行3. 静的解析・整形ツール
Resource/rector.php/Resource/.php-cs-fixer.dist.phpを追加(.php設定は本体のPlugin\:サービス検出で 500 を避けるためResource/配下に配置)4. CI(
.github/workflows/main.ymlほか)checkout@v4・$GITHUB_OUTPUT化TwoFactorAuthCustomer44を checkout / archive し、mock-package-api+eccube:composer:requireで依存解決のうえ有効化--ignore-platform-req=ext-redis: Symfony 7.4 のsymfony/cacheが古いphp-redisと衝突して本体 composer install が失敗するのを回避(redis は未使用)cache:warmup: 有効プラグインのルート確定のため warmup を実行(Tests がある場合のみ PHPUnit 実行)release.yml: 配布パッケージからResource/rector.php/Resource/.php-cs-fixer.dist.phpを除外テスト
release.yml相当)から開発用ファイルが除外されることを確認Summary by CodeRabbit