Repository navigation
48472: Fix blank page on LTI launches and fatal error with celtic/lti 5.4.4 - #12184
Merged
Saaweel merged 1 commit intoOct 8, 2026
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reported in Mantis 48472: updating the composer dependencies stops with a fatal error.
Since
celtic/lti5.4.4,Tool::handleRequest()is declared asnever, andilLTITooloverrides it withvoid. The^5.0.0constraint allows any 5.x release, socomposer updateinstalls 5.4.7 and the setup stops while building the artifacts.Blank page on LTI launches with the shipped library
Since 11.4,
composer.lockshipsceltic/lti5.4.3. From 5.4.0 on, the library ends the request indoExit()also after a valid launch, so ILIAS never gets control back to authenticate the user and forward them to the object: the launch returns HTTP 200 with an empty body. This is the problem fixed forrelease_10in #12104 (Mantis 48360), whichrelease_11did not get.Fix
ilLTIToolno longer overrideshandleRequest(). The preparation of the request moves to a newprocessRequest(), whichilAuthProviderLTIcalls instead. As nothing overrides the library method anymore, its return type no longer matters.processRequest()setsonExitExceptionClassto the newilLTIExitExceptionand catches it. A pending redirect back to the platform or a pending output (error page, cookie check form) is sent and ends the request, as before. Only a valid launch returns control to ILIAS. This is the same handling as inrelease_10.There are no changes to
composer.jsonorcomposer.lock. The new class needscomposer dump-autoload.The handler relies on the behaviour of
celtic/lti5.4.0 and later, which stores the response before ending the request. 5.3.x prints it itself, so it must not be combined with this change.composer.lockships 5.4.3.Testing
Verified live on an ILIAS 11.4 installation acting as LTI provider, with LTI 1.1 launches into a released course:
composer update celtic/ltiThe changed classes were also checked against
celtic/lti5.4.3 and 5.4.7 outside ILIAS: a valid launch returns control, an invalid one ends the request, and an error page without return URL is sent once.php-cs-fixerreports no violations.