fix(vikon): use correct token introspect endpoint for update system

Original vikon_core security.php validates tokens via:
  POST db-nica.ru/oauth2/resource/token/introspect
  Body: client_id=542&access_token=XXX

Our code was incorrectly using:
  GET auth.db-nica.ru/api/profile_applicant/check_access_token
  Header: Authorization: Bearer XXX

This was the WRONG endpoint — the profile check is for abitur forms,
not for the update system.
This commit is contained in:
F4ilji
2026-07-04 13:54:56 +05:00
parent a963647770
commit 967db81d3c
2 changed files with 7 additions and 5 deletions
@@ -28,6 +28,7 @@ class VikonServiceProvider extends ServiceProvider
$this->app->singleton(ValidateTokenTask::class, fn ($app) => new ValidateTokenTask(
http: $app->make(HttpTask::class),
clientId: config('vikon.client_id'),
));
$this->app->singleton(RefreshTokenTask::class, fn ($app) => new RefreshTokenTask(
@@ -8,16 +8,17 @@ class ValidateTokenTask
{
public function __construct(
private readonly HttpTask $http,
private readonly string $clientId,
) {}
public function run(string $accessToken): bool
{
try {
$response = $this->http->getWithToken(
'api/profile_applicant/check_access_token',
$accessToken,
'auth'
);
$response = $this->http->post('oauth2/resource/token/introspect', [
'client_id' => $this->clientId,
'access_token' => $accessToken,
]);
return $response->successful();
} catch (\Throwable $e) {
Log::warning('Vikon token validation failed', ['error' => $e->getMessage()]);