feat: phase 1 — InsForge session auth, role gates, refresh middleware, auth test suites
This commit is contained in:
@@ -0,0 +1,49 @@
|
||||
<?php
|
||||
|
||||
namespace App\Auth;
|
||||
|
||||
use App\Services\InsForge\InsForgeAuthService;
|
||||
use App\Services\InsForge\InsForgeException;
|
||||
use Illuminate\Contracts\Auth\Authenticatable as AuthenticatableContract;
|
||||
use Illuminate\Contracts\Auth\UserProvider;
|
||||
|
||||
class InsForgeUserProvider implements UserProvider
|
||||
{
|
||||
public function __construct(private readonly InsForgeAuthService $auth) {}
|
||||
|
||||
public function retrieveById($identifier): ?AuthenticatableContract
|
||||
{
|
||||
return $this->auth->profileById($identifier);
|
||||
}
|
||||
|
||||
public function retrieveByToken($identifier, #[\SensitiveParameter] $token): ?AuthenticatableContract
|
||||
{
|
||||
return null;
|
||||
}
|
||||
|
||||
public function updateRememberToken(AuthenticatableContract $user, #[\SensitiveParameter] $token): void {}
|
||||
|
||||
public function retrieveByCredentials(#[\SensitiveParameter] array $credentials): ?AuthenticatableContract
|
||||
{
|
||||
if (! isset($credentials['email'], $credentials['password']) || ! is_string($credentials['email'])) {
|
||||
return null;
|
||||
}
|
||||
|
||||
try {
|
||||
return $this->auth->attemptLogin($credentials['email'], (string) $credentials['password']);
|
||||
} catch (InsForgeException $exception) {
|
||||
if ($exception->getCode() === 401) {
|
||||
return null;
|
||||
}
|
||||
|
||||
throw $exception;
|
||||
}
|
||||
}
|
||||
|
||||
public function validateCredentials(AuthenticatableContract $user, #[\SensitiveParameter] array $credentials): bool
|
||||
{
|
||||
return true;
|
||||
}
|
||||
|
||||
public function rehashPasswordIfRequired(AuthenticatableContract $user, #[\SensitiveParameter] array $credentials, bool $force = false): void {}
|
||||
}
|
||||
Reference in New Issue
Block a user