Protect admin routes with new eloquent sessions

When using Laravel’s own auth middleware an exception would then get
thrown which was being sent to Slack, hmmm.

So I modified the original MyAuthMiddleware to use the Auth facade
instead of a custom session key.

A logout page has also been added.
This commit is contained in:
Jonny Barnes 2019-03-23 09:35:07 +00:00
parent db3708bbb6
commit 2e79492b01
4 changed files with 58 additions and 17 deletions

View file

@ -4,7 +4,6 @@ declare(strict_types=1);
namespace App\Http\Controllers; namespace App\Http\Controllers;
use Illuminate\View\View;
use Illuminate\Support\Facades\Auth; use Illuminate\Support\Facades\Auth;
use Illuminate\Http\RedirectResponse; use Illuminate\Http\RedirectResponse;
@ -40,4 +39,31 @@ class AuthController extends Controller
return redirect()->route('login'); return redirect()->route('login');
} }
/**
* Show the form to logout a user.
*
* @return \Illuminate\View\View|\Illuminate\Http\RedirectResponse
*/
public function showLogout()
{
if (Auth::check() === false) {
// The user is not logged in, just redirect them home
return redirect('/');
}
return view('logout');
}
/**
* Log the user out from their current session.
*
* @return \Illuminate\Http\RedirectResponse;
*/
public function logout(): RedirectResponse
{
Auth::logout();
return redirect('/');
}
} }

View file

@ -6,6 +6,7 @@ namespace App\Http\Middleware;
use Closure; use Closure;
use Illuminate\Http\Request; use Illuminate\Http\Request;
use Illuminate\Support\Facades\Auth;
class MyAuthMiddleware class MyAuthMiddleware
{ {
@ -18,7 +19,7 @@ class MyAuthMiddleware
*/ */
public function handle(Request $request, Closure $next) public function handle(Request $request, Closure $next)
{ {
if ($request->session()->has('loggedin') !== true) { if (Auth::check($request->user()) == false) {
//theyre not logged in, so send them to login form //theyre not logged in, so send them to login form
return redirect()->route('login'); return redirect()->route('login');
} }

View file

@ -0,0 +1,10 @@
@extends('master')
@section('title')Logout @stop
@section('content')
<h2>Logout</h2>
<form action="logout" method="post">
<input type="hidden" name="_token" value="{{ csrf_token() }}">
<input type="submit" name="submit" value="Logout">
</form>
@stop

View file

@ -20,10 +20,14 @@ Route::group(['domain' => config('url.longurl')], function () {
// Static colophon page // Static colophon page
Route::view('colophon', 'colophon'); Route::view('colophon', 'colophon');
//The login routes to get authe'd for admin // The login routes to get auth'd for admin
Route::get('login', 'AuthController@showLogin')->name('login'); Route::get('login', 'AuthController@showLogin')->name('login');
Route::post('login', 'AuthController@login'); Route::post('login', 'AuthController@login');
// And the logout routes
Route::get('logout', 'AuthController@showLogout')->name('logout');
Route::post('logout', 'AuthController@logout');
// Admin pages grouped for filter // Admin pages grouped for filter
Route::group([ Route::group([
'middleware' => 'myauth', 'middleware' => 'myauth',
@ -139,7 +143,7 @@ Route::group(['domain' => config('url.longurl')], function () {
Route::post('api/media', 'MicropubController@media')->middleware('micropub.token', 'cors')->name('media-endpoint'); Route::post('api/media', 'MicropubController@media')->middleware('micropub.token', 'cors')->name('media-endpoint');
Route::options('/api/media', 'MicropubController@mediaOptionsResponse')->middleware('cors'); Route::options('/api/media', 'MicropubController@mediaOptionsResponse')->middleware('cors');
//webmention // Webmention
Route::get('webmention', 'WebMentionsController@get'); Route::get('webmention', 'WebMentionsController@get');
Route::post('webmention', 'WebMentionsController@receive'); Route::post('webmention', 'WebMentionsController@receive');