Problem/Motivation
#2218651: [meta] Make Drupal compatible with persistent app servers like ReactPHP, PHP-PM, PHPFastCGI, FrankenPHP, Swoole is slowly gaining momentum and with #3553275: Drupal now uses symfony/runtime for bootstrap separation it is easier to use persistent app servers like FrankenPHP with Drupal. However, this module's use of a single nonce per service instatiantiation means that, in FrankenPHP's worker mode, the wrong nonce can be served because it will be used with every request.
Proposed resolution
Attach the nonce to RequestStack, so that each request gets a different nonce. (Do not assume that one Drupal bootstrap = one request.)
Issue fork csp-3624646
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
ptmkenny commentedComment #4
ptmkenny commentedComment #5
jparmar commentedReviewed MR !68
Code review:
- Nonce moved from service-lifetime property to main-request attributes via RequestStack — correct for FrankenPHP worker mode.
- Subrequests reuse the main-request nonce; a new main request gets a new nonce.
- Empty RequestStack throws LogicException as expected.
- No services.yml change needed (autowire already on).
- Unit tests cover same-request, subrequest, new-request, and no-request cases.
verified locally on PHP 8.3: mirrored NonceTest assertions — 7/7 passed, including worker-style reuse of the same Nonce service across requests.
Comment #6
gappleThank you :)