feat: phase 1 — InsForge session auth, role gates, refresh middleware, auth test suites

This commit is contained in:
sean
2026-08-25 18:01:11 +07:00
parent 046cefc56c
commit aad2b5e256
15 changed files with 613 additions and 36 deletions
+49
View File
@@ -0,0 +1,49 @@
<?php
namespace App\Auth;
use App\Services\InsForge\InsForgeAuthService;
use App\Services\InsForge\InsForgeException;
use Illuminate\Contracts\Auth\Authenticatable as AuthenticatableContract;
use Illuminate\Contracts\Auth\UserProvider;
class InsForgeUserProvider implements UserProvider
{
public function __construct(private readonly InsForgeAuthService $auth) {}
public function retrieveById($identifier): ?AuthenticatableContract
{
return $this->auth->profileById($identifier);
}
public function retrieveByToken($identifier, #[\SensitiveParameter] $token): ?AuthenticatableContract
{
return null;
}
public function updateRememberToken(AuthenticatableContract $user, #[\SensitiveParameter] $token): void {}
public function retrieveByCredentials(#[\SensitiveParameter] array $credentials): ?AuthenticatableContract
{
if (! isset($credentials['email'], $credentials['password']) || ! is_string($credentials['email'])) {
return null;
}
try {
return $this->auth->attemptLogin($credentials['email'], (string) $credentials['password']);
} catch (InsForgeException $exception) {
if ($exception->getCode() === 401) {
return null;
}
throw $exception;
}
}
public function validateCredentials(AuthenticatableContract $user, #[\SensitiveParameter] array $credentials): bool
{
return true;
}
public function rehashPasswordIfRequired(AuthenticatableContract $user, #[\SensitiveParameter] array $credentials, bool $force = false): void {}
}