mirror of
https://github.com/solidtime-io/solidtime.git
synced 2026-08-14 11:12:16 +01:00
Updated dependencies; Major update laravel passport
This commit is contained in:
@@ -7,11 +7,12 @@ namespace Database\Factories\Passport;
|
||||
use App\Models\Passport\Client;
|
||||
use App\Models\User;
|
||||
use Illuminate\Database\Eloquent\Factories\Factory;
|
||||
use Laravel\Passport\Database\Factories\ClientFactory as BaseClientFactory;
|
||||
|
||||
/**
|
||||
* @extends Factory<Client>
|
||||
*/
|
||||
class ClientFactory extends Factory
|
||||
class ClientFactory extends BaseClientFactory
|
||||
{
|
||||
/**
|
||||
* Define the model's default state.
|
||||
@@ -22,13 +23,13 @@ class ClientFactory extends Factory
|
||||
{
|
||||
return [
|
||||
'id' => $this->faker->uuid,
|
||||
'user_id' => null,
|
||||
'owner_id' => null,
|
||||
'owner_type' => null,
|
||||
'name' => $this->faker->company(),
|
||||
'secret' => $this->faker->regexify('[A-Za-z]{40}'),
|
||||
'provider' => 'users',
|
||||
'redirect' => $this->faker->url(),
|
||||
'personal_access_client' => false,
|
||||
'password_client' => false,
|
||||
'redirect_uris' => [$this->faker->url()],
|
||||
'grant_types' => [],
|
||||
'revoked' => false,
|
||||
'created_at' => $this->faker->dateTime(),
|
||||
'updated_at' => $this->faker->dateTime(),
|
||||
@@ -39,7 +40,7 @@ class ClientFactory extends Factory
|
||||
{
|
||||
return $this->state(function (array $attributes) {
|
||||
return [
|
||||
'personal_access_client' => true,
|
||||
'grant_types' => ['personal_access'],
|
||||
];
|
||||
});
|
||||
}
|
||||
@@ -48,7 +49,8 @@ class ClientFactory extends Factory
|
||||
{
|
||||
return $this->state(function (array $attributes) use ($user): array {
|
||||
return [
|
||||
'user_id' => $user->getKey(),
|
||||
'owner_id' => $user->getKey(),
|
||||
'owner_type' => (new User)->getMorphClass(),
|
||||
];
|
||||
});
|
||||
}
|
||||
|
||||
@@ -0,0 +1,44 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
/**
|
||||
* Run the migrations.
|
||||
*/
|
||||
public function up(): void
|
||||
{
|
||||
Schema::create('oauth_device_codes', function (Blueprint $table): void {
|
||||
$table->char('id', 80)->primary();
|
||||
$table->foreignId('user_id')->nullable()->index();
|
||||
$table->foreignUuid('client_id')->index();
|
||||
$table->char('user_code', 8)->unique();
|
||||
$table->text('scopes');
|
||||
$table->boolean('revoked');
|
||||
$table->dateTime('user_approved_at')->nullable();
|
||||
$table->dateTime('last_polled_at')->nullable();
|
||||
$table->dateTime('expires_at')->nullable();
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Reverse the migrations.
|
||||
*/
|
||||
public function down(): void
|
||||
{
|
||||
Schema::dropIfExists('oauth_device_codes');
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the migration connection name.
|
||||
*/
|
||||
public function getConnection(): ?string
|
||||
{
|
||||
return $this->connection ?? config('passport.connection');
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,35 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
/**
|
||||
* Run the migrations.
|
||||
*/
|
||||
public function up(): void
|
||||
{
|
||||
Schema::drop('oauth_personal_access_clients');
|
||||
}
|
||||
|
||||
/**
|
||||
* Reverse the migrations.
|
||||
*/
|
||||
public function down(): void
|
||||
{
|
||||
Schema::create('oauth_personal_access_clients', function (Blueprint $table): void {
|
||||
$table->bigIncrements('id');
|
||||
$table->uuid('client_id');
|
||||
$table->foreign('client_id')
|
||||
->references('id')
|
||||
->on('oauth_clients')
|
||||
->onDelete('restrict')
|
||||
->onUpdate('cascade');
|
||||
$table->timestamps();
|
||||
});
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,97 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
use Illuminate\Database\Schema\Blueprint;
|
||||
use Illuminate\Support\Facades\Schema;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
/**
|
||||
* Run the migrations.
|
||||
*/
|
||||
public function up(): void
|
||||
{
|
||||
DB::table('oauth_clients')->update(['provider' => 'users']); // Change default provider if necessary
|
||||
|
||||
Schema::table('oauth_clients', function (Blueprint $table): void {
|
||||
$table->text('grant_types')->default('[]')->after('provider');
|
||||
$table->text('redirect_uris')->default('[]');
|
||||
$table->renameColumn('user_id', 'owner_id');
|
||||
$table->string('owner_type')->after('owner_id')->nullable();
|
||||
});
|
||||
DB::table('oauth_clients')
|
||||
->where('personal_access_client', 1)
|
||||
->update(['grant_types' => ['personal_access']]);
|
||||
DB::table('oauth_clients')
|
||||
->where('password_client', 1)
|
||||
->update(['grant_types' => ['password', 'refresh_token']]);
|
||||
DB::table('oauth_clients')
|
||||
->where('password_client', 0)
|
||||
->where('personal_access_client', 0)
|
||||
->update(['grant_types' => ['client_credentials']]);
|
||||
|
||||
DB::table('oauth_clients')
|
||||
->whereNotNull('owner_id')
|
||||
->update(['owner_type' => 'user']); // Value might be class name of the owner model, depends on if you use "enforceMorphMap"
|
||||
|
||||
DB::table('oauth_clients')->eachById(function ($client): void {
|
||||
$redirectUris = [$client->redirect];
|
||||
DB::table('oauth_clients')
|
||||
->where('id', $client->id)
|
||||
->update([
|
||||
'redirect_uris' => $redirectUris,
|
||||
]);
|
||||
});
|
||||
|
||||
Schema::table('oauth_clients', function (Blueprint $table): void {
|
||||
$table->dropForeign(['user_id']);
|
||||
$table->index(['owner_id', 'owner_type']);
|
||||
$table->dropColumn('redirect');
|
||||
$table->dropColumn('personal_access_client');
|
||||
$table->dropColumn('password_client');
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Reverse the migrations.
|
||||
*/
|
||||
public function down(): void
|
||||
{
|
||||
Schema::table('oauth_clients', function (Blueprint $table): void {
|
||||
$table->dropIndex(['owner_id', 'owner_type']);
|
||||
$table->renameColumn('owner_id', 'user_id');
|
||||
$table->foreign('user_id')
|
||||
->on('users')
|
||||
->references('id')
|
||||
->onDelete('cascade')
|
||||
->onUpdate('cascade');
|
||||
$table->string('redirect')->nullable();
|
||||
$table->boolean('personal_access_client')->default(false);
|
||||
$table->boolean('password_client')->default(false);
|
||||
});
|
||||
|
||||
DB::table('oauth_clients')->eachById(function ($client): void {
|
||||
$redirectUris = json_decode($client->redirect_uris);
|
||||
$grantTypes = json_decode($client->grant_types);
|
||||
|
||||
DB::table('oauth_clients')
|
||||
->where('id', $client->id)
|
||||
->update([
|
||||
'redirect' => $redirectUris[0] ?? '', // redirect not nullable
|
||||
'password_client' => in_array('password', $grantTypes, true)
|
||||
&& in_array('refresh_token', $grantTypes, true),
|
||||
'personal_access_client' => in_array('personal_access', $grantTypes, true),
|
||||
]);
|
||||
});
|
||||
|
||||
Schema::table('oauth_clients', function (Blueprint $table): void {
|
||||
$table->dropColumn(['grant_types', 'redirect_uris', 'owner_type']);
|
||||
$table->string('redirect')->nullable(false)->change();
|
||||
$table->boolean('personal_access_client')->default(null)->change();
|
||||
$table->boolean('password_client')->default(null)->change();
|
||||
});
|
||||
|
||||
}
|
||||
};
|
||||
35
database/migrations/2025_07_15_105949_hash_oauth_clients.php
Normal file
35
database/migrations/2025_07_15_105949_hash_oauth_clients.php
Normal file
@@ -0,0 +1,35 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
use Illuminate\Database\Migrations\Migration;
|
||||
|
||||
return new class extends Migration
|
||||
{
|
||||
/**
|
||||
* Run the migrations.
|
||||
*/
|
||||
public function up(): void
|
||||
{
|
||||
// This could be optimized to run all the updates in the eachById
|
||||
DB::table('oauth_clients')->eachById(function ($client): void {
|
||||
$secret = $client->secret;
|
||||
if (Hash::isHashed($secret) && ! Hash::needsRehash($secret)) {
|
||||
return; // Already hashed and not needing rehash
|
||||
}
|
||||
DB::table('oauth_clients')
|
||||
->where('id', $client->id)
|
||||
->update([
|
||||
'secret' => Hash::make($secret),
|
||||
]);
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Reverse the migrations.
|
||||
*/
|
||||
public function down(): void
|
||||
{
|
||||
// This can not be reversed without a backup of the original secrets, for security reasons.
|
||||
}
|
||||
};
|
||||
@@ -24,7 +24,6 @@ use Illuminate\Support\Facades\DB;
|
||||
use Laravel\Passport\AuthCode;
|
||||
use Laravel\Passport\Client as PassportClient;
|
||||
use Laravel\Passport\ClientRepository;
|
||||
use Laravel\Passport\PersonalAccessClient;
|
||||
use Laravel\Passport\RefreshToken;
|
||||
use Laravel\Passport\Token;
|
||||
|
||||
@@ -37,6 +36,18 @@ class DatabaseSeeder extends Seeder
|
||||
{
|
||||
$this->deleteAll();
|
||||
|
||||
app(ClientRepository::class)->createAuthorizationCodeGrantClient(
|
||||
name: 'Desktop App',
|
||||
redirectUris: ['solidtime://oauth/callback'],
|
||||
confidential: false, // TODO: ?
|
||||
enableDeviceFlow: false, // TODO: ?
|
||||
);
|
||||
|
||||
// TODO: grant_types ? migration?
|
||||
|
||||
// app(ClientRepository::class)->createPersonalAccessGrantClient('API');
|
||||
|
||||
/*
|
||||
app(ClientRepository::class)->create(
|
||||
null,
|
||||
'desktop',
|
||||
@@ -46,17 +57,16 @@ class DatabaseSeeder extends Seeder
|
||||
false,
|
||||
false
|
||||
);
|
||||
*/
|
||||
|
||||
$personalAccessClient = new PassportClient;
|
||||
$personalAccessClient->id = config('passport.personal_access_client.id');
|
||||
$personalAccessClient->secret = config('passport.personal_access_client.secret');
|
||||
$personalAccessClient->name = 'API';
|
||||
$personalAccessClient->redirect = 'http://localhost';
|
||||
$personalAccessClient->user_id = null;
|
||||
$personalAccessClient->redirect_uris = ['http://localhost'];
|
||||
$personalAccessClient->revoked = false;
|
||||
$personalAccessClient->provider = null;
|
||||
$personalAccessClient->personal_access_client = true;
|
||||
$personalAccessClient->password_client = false;
|
||||
$personalAccessClient->provider = 'users';
|
||||
$personalAccessClient->grant_types = ['personal_access'];
|
||||
$personalAccessClient->save();
|
||||
|
||||
$userWithMultipleOrganizations = User::factory()->withPersonalOrganization()->create([
|
||||
@@ -197,7 +207,6 @@ class DatabaseSeeder extends Seeder
|
||||
DB::table((new RefreshToken)->getTable())->delete();
|
||||
DB::table((new Token)->getTable())->delete();
|
||||
DB::table((new AuthCode)->getTable())->delete();
|
||||
DB::table((new PersonalAccessClient)->getTable())->delete();
|
||||
DB::table((new PassportClient)->getTable())->delete();
|
||||
|
||||
// Internal tables
|
||||
|
||||
Reference in New Issue
Block a user