chore(phpstan): use unsealed array shapes for credentials#1330
Merged
Conversation
michalsn
approved these changes
May 30, 2026
Collaborator
Author
|
Thanks! |
Member
|
Sorry to be late to the show, but |
5 tasks
Collaborator
Author
|
@paulbalandan Thanks for pointing that out! you were absolutely right. I’ve opened a follow-up PR #1332 to correct this and restrict the extra credential keys accordingly. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR fixes PHPStan errors related to extra keys being passed to the
$credentialsarray in Authenticators.Since Shield natively allows logging in with custom columns (via Auth.validFields) instead of just
emailorusername, the strictly sealed array shapes in the DocBlocks were causing static analysis to fail when custom keys (like phone) were passed.To solve this while preserving IDE autocomplete, I used PHPStan’s unsealed array shape feature by appending
...to the array definitions. This tells PHPStan to expect the defined keys but also safely allow extra custom columns without throwing the Extra keys are not allowed error.see :
https://github.com/codeigniter4/shield/actions/runs/26674339169/job/78623302872
ref:
https://phpstan.org/blog/phpstan-2-2-unsealed-array-shapes-safer-array-keys
Checklist: