mirror of
https://github.com/solidtime-io/solidtime.git
synced 2026-08-14 11:12:16 +01:00
Add core support for extendable authentication
add support for passwordless user creation; add filament loading support for new laravel modules namespacing; add support for pluggable password reset and login rules
This commit is contained in:
@@ -25,6 +25,73 @@ use Laravel\Fortify\Fortify;
|
||||
|
||||
class FortifyServiceProvider extends ServiceProvider
|
||||
{
|
||||
/**
|
||||
* Dummy bcrypt hash compared against when no user matches the submitted
|
||||
* email. Hash::check is run against it so login takes the same time whether
|
||||
* or not the email exists — otherwise an unknown email would skip the
|
||||
* (deliberately slow) hash and return faster, letting an attacker enumerate
|
||||
* registered accounts by timing the response. The plaintext is irrelevant:
|
||||
* it is only ever checked against attacker-supplied input and never matches.
|
||||
*/
|
||||
private const ABSENT_USER_PASSWORD_HASH = '$2y$12$92IXUNpkjO0rOQ5byMi.Ye4oKoEa3Ro9llC/.og/at2.uheWG/igi';
|
||||
|
||||
/**
|
||||
* Authorization rules applied AFTER the password is verified. Each rule
|
||||
* receives the authenticated user + request and returns whether the login
|
||||
* may proceed; any rule returning false denies it. This is an extension
|
||||
* point: modules (e.g. SSO enforcement) add a rule to veto a password login
|
||||
* instead of replacing this credential check — which would silently drift
|
||||
* from the host logic the next time it changes.
|
||||
*
|
||||
* @var array<int, \Closure(User, Request): bool>
|
||||
*/
|
||||
protected static array $loginRules = [];
|
||||
|
||||
/**
|
||||
* Authorization rules applied before a password reset is completed. Rules
|
||||
* receive the user being reset + submitted input and return whether the
|
||||
* local reset flow may set a new password for that account.
|
||||
*
|
||||
* @var array<int, \Closure(User, array<string, mixed>): bool>
|
||||
*/
|
||||
protected static array $passwordResetRules = [];
|
||||
|
||||
/**
|
||||
* Register an additional rule that gates password login (see $loginRules).
|
||||
*
|
||||
* @param \Closure(User, Request): bool $rule
|
||||
*/
|
||||
public static function authenticateUsingRule(\Closure $rule): void
|
||||
{
|
||||
static::$loginRules[] = $rule;
|
||||
}
|
||||
|
||||
/**
|
||||
* Register an additional rule that gates password reset completion.
|
||||
*
|
||||
* @param \Closure(User, array<string, mixed>): bool $rule
|
||||
*/
|
||||
public static function resetPasswordUsingRule(\Closure $rule): void
|
||||
{
|
||||
static::$passwordResetRules[] = $rule;
|
||||
}
|
||||
|
||||
/**
|
||||
* Check whether the given user may complete the local password reset flow.
|
||||
*
|
||||
* @param array<string, mixed> $input
|
||||
*/
|
||||
public static function canResetPassword(User $user, array $input = []): bool
|
||||
{
|
||||
foreach (static::$passwordResetRules as $rule) {
|
||||
if (! $rule($user, $input)) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Register any application services.
|
||||
*/
|
||||
@@ -92,7 +159,23 @@ class FortifyServiceProvider extends ServiceProvider
|
||||
->where('is_placeholder', '=', false)
|
||||
->first();
|
||||
|
||||
if ($user !== null && Hash::check($request->password, $user->password)) {
|
||||
// Always run the hash check — against the real hash, or a dummy when
|
||||
// there is no user — so login timing is identical either way (see
|
||||
// ABSENT_USER_PASSWORD_HASH). Passwordless accounts (SSO-only users
|
||||
// have password = null) fail here, so they cannot password-login.
|
||||
$existingPasswordHash = $user->password ?? self::ABSENT_USER_PASSWORD_HASH;
|
||||
|
||||
$passwordIsValid = Hash::check((string) $request->password, $existingPasswordHash);
|
||||
|
||||
if ($user !== null && $passwordIsValid) {
|
||||
// Credentials are valid; now apply any registered authorization
|
||||
// rules (e.g. SSO enforcement may still block password login).
|
||||
foreach (static::$loginRules as $rule) {
|
||||
if (! $rule($user, $request)) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
return $user;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user