Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Clarify signing request expiration and access renewal messages

Closed Beginner friendly
#8,713 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
84/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
php
Domain
backend

Research direction

Start in lib/Service/IdentifyMethod/AbstractIdentifyMethod.php by reading throwIfMaximumValidityExpired(), throwIfRenewalIntervalExpired(), and validateToRenew(). Run the affected PHPUnit tests and normal PHP static checks, then update only the public wording and coverage so signing-request expiry is distinct from renewable access expiry, renewal remains blocked after maximum validity, and no internal policy data is exposed.

Written by the indexing model from the issue text.

Description

backend enhancement good first issue php

Goal

Use clear backend messages for two different cases:

  1. the signing request has reached its maximum validity and cannot be used anymore;
  2. signer access has expired but can still be renewed while the signing request is valid.

Do not change expiration or renewal calculations.

Current code

Start with:

lib/Service/IdentifyMethod/AbstractIdentifyMethod.php

Review these methods:

throwIfMaximumValidityExpired()
throwIfRenewalIntervalExpired()
validateToRenew()

Today, maximum validity can return the generic message Link expired.. This message does not explain that the whole signing request has expired.

Required behavior

For maximum validity, use wording about the signing request.

For renewal interval, use wording about access or the signing link.

Keep the current rule that renewal is not allowed after maximum validity has expired.

Security and privacy

These messages can be shown to public signers.

  • Do not expose policy keys, policy values, user IDs, group IDs, internal paths, or stack traces.
  • Keep email addresses masked where the current renewal flow already masks them.
  • Do not change actions, UUID handling, status codes, or authentication checks.
  • Do not return raw exception details to make the message more descriptive.

Target branch

main

Milestone: Next Major (36)

Tests

Cover:

  • maximum validity expired;
  • renewal interval expired while the request is still valid;
  • renewal blocked after maximum validity has expired;
  • the existing renewal action is unchanged;
  • public error payloads do not expose internal policy data.

Run the affected PHPUnit tests and the normal PHP static checks.

Done when

  • Maximum validity uses signing-request wording.
  • Renewal uses access/link wording.
  • Renewal behavior is unchanged.
  • Public messages do not expose internal data.
  • Tests pass.

Good first issue

This is a small backend text and test change. Do not refactor the expiration flow.

Additional context
  • If you have questions, feel free to ask in this issue.
  • Give a ⭐️ star to this repository if you find LibreSign useful and would like to support the project.
  • You can also join our community: https://t.me/LibreSign
Dominant language
PHP
Stars
818
Forks
146
Avg merge
7h 8m
Merged PRs (30d)
549

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from LibreSign/libresign

All issues in LibreSign/libresign

Similar issues

More PHP issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.