Skip to content

feat(profile): endpoint mobile de leitura do perfil (Feature 3) - #566

Merged
danielhe4rt merged 1 commit into
he4rt:4.xfrom
tecrodrigocastro:story/531-api-mobile-profile
Oct 4, 2026
Merged

danielhe4rt merged 1 commit into
he4rt:4.xfrom
tecrodrigocastro:story/531-api-mobile-profile

Conversation

@tecrodrigocastro

@tecrodrigocastro tecrodrigocastro commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Feature 3 do plano (docs/plans/2026-09-22-api-mobile-jwt.md): endpoint de leitura do perfil do usuário autenticado para o app mobile. Depende da #565 (já mergeada na 4.x).

Summary

  • GET /api/mobile/profile (atrás de auth:api) retorna o perfil via ProfileResource: dados profissionais (nickname, headline, seniority, anos de experiência, about, social_links), disponibilidade/preferências, skills e experiências profissionais.
  • v1 é só leitura, conforme o PRD ("visualização do próprio perfil").
  • MobileProfileController reaproveita Profile::ensureExists(auth()->id()), já usado no resto do domínio.
  • Corrigido um detalhe do ResourceResponse padrão do Laravel: quando o profile é criado na hora (primeiro acesso), ele devolveria 201 numa rota GET — forçado 200 explicitamente.

Test plan

  • vendor/bin/pint --test
  • vendor/bin/phpstan analyse app-modules/profile/src --memory-limit=1G (0 erros)
  • vendor/bin/pest app-modules/profile/tests (73 testes passando, incluindo os 3 novos do endpoint)
  • Testado manualmente via tinker (payload do ProfileResource conferido)

@tecrodrigocastro
tecrodrigocastro requested a review from a team September 25, 2026 14:28
@tecrodrigocastro
tecrodrigocastro marked this pull request as draft September 25, 2026 14:29
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository YAML (base), Central YAML (inherited)
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 3b99fe85-a72b-4743-8451-8e3988ece291
📥 Commits

Reviewing files that changed from the base of the PR and between 39d9de6 and 57997ae.

📒 Files selected for processing (1)
  • docs/plans/2026-09-22-api-mobile-jwt.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • docs/plans/2026-09-22-api-mobile-jwt.md

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

Adds an authenticated GET /api/mobile/profile endpoint. The controller ensures a profile exists, loads skills and work experiences, and returns serialized profile data. Feature tests cover unauthenticated access, default profile creation, and populated profile responses.

Suggested reviewers: danielhe4rt

Priority: ⬇️ Low

Change: Feature

Merge Risk: ⚪ Minimal · up to 57997

The reviewed change only updates a planning document, so there is no identified behavior or production risk. The PR description says the endpoint depends on PR #565, so merge order should be respected.

Security Architecture Review

Security architecture risk: 🟠 High · up to 39d9d

The new mobile sign-in flow sends a short-lived login code through a configurable app link. If another app receives that link, it could exchange the code for the user’s token. The example cache setting also does not provide the shared storage this authentication flow needs. The actual mobile-link handling and production cache settings remain unverified.

Retained concerns

  • High · security · inferred: The new callback places a redeemable login code in a configurable custom-scheme link. If another installed app receives that link before the intended app, it can use the public exchange endpoint to obtain the user’s JWT; the server does not bind redemption to the initiating client or device. Actual interception depends on mobile-platform and app-link handling not present in the evidence.
  • Medium · security · inferred: The newly cache-dependent authentication flow has no established shared production cache in the supplied evidence. If deployed with the example array cache, exchange codes and locks are not shared across workers or requests, and cache-backed JWT revocation cannot provide a reliable cross-worker logout guarantee.
Security review details

Security Blast Radius

  • inferred — A successfully intercepted exchange code yields a JWT for its associated user, exposing that user’s authenticated mobile endpoints, including their profile. The evidence does not establish tenant-wide or administrative authority.

Security Findings and Attack Paths

  • inferred — The new bearer-code link creates a conditional interception path from mobile link handling to JWT issuance. The supplied evidence neither demonstrates interception on the intended mobile platform nor establishes a client-side control that rules it out.

Trust Boundaries and Controls

  • observed — Mobile OAuth limits redirect initiation to supported providers and uses encrypted state. The handoff code is random, expires after 60 seconds, and is normally consumed once under a per-code lock; exchange and refresh are public, whereas logout, current-user, and profile routes require API authentication.
  • observed — Provider identity resolution first matches an existing external identity, then falls back to matching an account by email. This matching action is unchanged in the target diff; provider-specific email assurance is not established uniformly by the inspected clients.

Resilience and Maintainability Implications

  • inferred — The at-most-once handoff depends on a cache lock shared by all exchange workers and on its 10-second lease covering the read-and-delete operation. The supplied configuration does not establish those production conditions.

Hardening Proposals

  • proposed — Use a mobile callback with verified app ownership and bind code redemption to the initiating client; validate the deployed link behavior against another app claiming the configured scheme.
  • proposed — Specify and verify a shared production cache for exchange locks, codes, and JWT revocation before enabling mobile authentication across workers.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 32.26% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 31 functions across 30 files. (1 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed O título descreve de forma clara e concisa o endpoint de leitura do perfil mobile.
Description check ✅ Passed A descrição informa o contexto, as alterações e os testes executados. A seção de evidências foi omitida, o que é permitido para alterações sem impacto visual, e a dependência da PR #565 está identific…
Full details: Docstring Coverage

Explanation

Docstring coverage is 32.26% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 31 functions across 30 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

GET /api/mobile/profile retorna o perfil do usuário autenticado
(profissional, skills e experiências), via ProfileResource. v1
só leitura, conforme o PRD.

Depende da story/531-api-mobile-auth-jwt (guard JWT `api`).
@tecrodrigocastro
tecrodrigocastro force-pushed the story/531-api-mobile-profile branch from 39d9de6 to 57997ae Compare October 4, 2026 12:43
@tecrodrigocastro
tecrodrigocastro marked this pull request as ready for review October 4, 2026 12:43
@danielhe4rt
danielhe4rt merged commit e77729a into he4rt:4.x Oct 4, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants