Skip to content

48472: Fix blank page on LTI launches and fatal error with celtic/lti 5.4.4 - #12184

Merged
Saaweel merged 1 commit into
ILIAS-eLearning:release_11from
surlabs:ilias11_LTI_fix_celtic_5_4
Oct 8, 2026
Merged

Saaweel merged 1 commit into
ILIAS-eLearning:release_11from
surlabs:ilias11_LTI_fix_celtic_5_4

Conversation

@Saaweel

@Saaweel Saaweel commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Reported in Mantis 48472: updating the composer dependencies stops with a fatal error.

PHP Fatal error:  Declaration of ilLTITool::handleRequest(?bool $strictMode = null, bool $disableCookieCheck = false, bool $generateWarnings = false): void must be compatible with ceLTIc\LTI\Tool::handleRequest(?bool $strictMode = null, bool $disableCookieCheck = false, bool $generateWarnings = false): never

Since celtic/lti 5.4.4, Tool::handleRequest() is declared as never, and ilLTITool overrides it with void. The ^5.0.0 constraint allows any 5.x release, so composer update installs 5.4.7 and the setup stops while building the artifacts.

Blank page on LTI launches with the shipped library

Since 11.4, composer.lock ships celtic/lti 5.4.3. From 5.4.0 on, the library ends the request in doExit() also after a valid launch, so ILIAS never gets control back to authenticate the user and forward them to the object: the launch returns HTTP 200 with an empty body. This is the problem fixed for release_10 in #12104 (Mantis 48360), which release_11 did not get.

Fix

  • ilLTITool no longer overrides handleRequest(). The preparation of the request moves to a new processRequest(), which ilAuthProviderLTI calls instead. As nothing overrides the library method anymore, its return type no longer matters.
  • processRequest() sets onExitExceptionClass to the new ilLTIExitException and catches it. A pending redirect back to the platform or a pending output (error page, cookie check form) is sent and ends the request, as before. Only a valid launch returns control to ILIAS. This is the same handling as in release_10.

There are no changes to composer.json or composer.lock. The new class needs composer dump-autoload.

The handler relies on the behaviour of celtic/lti 5.4.0 and later, which stores the response before ending the request. 5.3.x prints it itself, so it must not be combined with this change. composer.lock ships 5.4.3.

Testing

Verified live on an ILIAS 11.4 installation acting as LTI provider, with LTI 1.1 launches into a released course:

Without the fix, 5.4.3 With the fix, 5.4.3 With the fix, 5.4.7
Valid launch HTTP 200, empty body Redirects to the course Redirects to the course (new and existing user)
Invalid signature Redirects back to the platform with the error Same Same
composer update celtic/lti All artifacts are built, no fatal error

The changed classes were also checked against celtic/lti 5.4.3 and 5.4.7 outside ILIAS: a valid launch returns control, an invalid one ends the request, and an error page without return URL is sent once. php-cs-fixer reports no violations.

@Saaweel Saaweel added bugfix php Pull requests that update Php code labels Oct 8, 2026
@Saaweel Saaweel self-assigned this Oct 8, 2026
@Saaweel
Saaweel merged commit 2a797b9 into ILIAS-eLearning:release_11 Oct 8, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix php Pull requests that update Php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant