feat: phase 1 — InsForge session auth, role gates, refresh middleware, auth test suites

This commit is contained in:
sean
2026-08-25 18:01:11 +07:00
parent 046cefc56c
commit aad2b5e256
15 changed files with 613 additions and 36 deletions
+23 -1
View File
@@ -2,12 +2,26 @@
namespace App\Providers;
use App\Auth\InsForgeUserProvider;
use App\Models\User;
use App\Services\InsForge\InsForgeAuthService;
use App\Services\InsForge\InsForgeClient;
use Illuminate\Contracts\Foundation\Application;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\Gate;
use Illuminate\Support\ServiceProvider;
class AppServiceProvider extends ServiceProvider
{
private const ADMIN_ONLY_ABILITIES = [
'manage-products',
'manage-stock',
'manage-drivers',
'manage-users',
'view-reports',
'view-activity-logs',
];
/**
* Register any application services.
*/
@@ -22,6 +36,8 @@ class AppServiceProvider extends ServiceProvider
$config['timeout'],
);
});
Auth::provider('insforge', fn () => new InsForgeUserProvider($this->app->make(InsForgeAuthService::class)));
}
/**
@@ -29,6 +45,12 @@ class AppServiceProvider extends ServiceProvider
*/
public function boot(): void
{
//
Gate::before(function (User $user, string $ability) {
if ($user->isAdmin()) {
return true;
}
return in_array($ability, self::ADMIN_ONLY_ABILITIES) ? false : null;
});
}
}
@@ -2,6 +2,7 @@
namespace App\Providers\Filament;
use App\Http\Middleware\RefreshInsForgeToken;
use Filament\Http\Middleware\Authenticate;
use Filament\Http\Middleware\AuthenticateSession;
use Filament\Http\Middleware\DisableBladeIconComponents;
@@ -51,6 +52,7 @@ class AdminPanelProvider extends PanelProvider
SubstituteBindings::class,
DisableBladeIconComponents::class,
DispatchServingFilamentEvent::class,
RefreshInsForgeToken::class,
])
->authMiddleware([
Authenticate::class,