trypost/app/Http/Controllers/Auth/LinkedInPageController.php

283 lines
11 KiB
PHP
Raw Normal View History

2026-01-15 01:13:44 +00:00
<?php
declare(strict_types=1);
2026-01-15 01:13:44 +00:00
namespace App\Http\Controllers\Auth;
use App\Enums\SocialAccount\Platform as SocialPlatform;
use App\Enums\SocialAccount\Status;
2026-01-15 01:13:44 +00:00
use App\Models\Workspace;
use App\Services\Social\LinkedInTokenSynchronizer;
2026-01-15 01:13:44 +00:00
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Http;
use Illuminate\Support\Facades\Log;
use Illuminate\View\View;
2026-01-15 01:13:44 +00:00
use Inertia\Inertia;
use Inertia\Response;
use Laravel\Socialite\Facades\Socialite;
use Symfony\Component\HttpFoundation\Response as SymfonyResponse;
class LinkedInPageController extends SocialController
{
protected string $driver = 'linkedin-openid';
protected SocialPlatform $platform = SocialPlatform::LinkedInPage;
protected array $scopes = [
'openid',
'profile',
'email',
'w_organization_social',
'r_organization_social',
'rw_organization_admin',
'w_member_social',
];
public function connect(Request $request): SymfonyResponse|RedirectResponse
2026-01-15 01:13:44 +00:00
{
$this->ensurePlatformEnabled();
$workspace = $request->user()->currentWorkspace;
if (! $workspace) {
return redirect()->route('app.workspaces.create');
}
2026-01-15 17:24:39 +00:00
$this->authorize('manageAccounts', $workspace);
$this->ensureSocialAccountLimit($workspace);
2026-01-15 01:13:44 +00:00
session([
'social_connect_workspace' => $workspace->id,
'linkedin_page_reconnect_id' => null,
'social_connect_onboarding' => $request->boolean('onboarding'),
]);
2026-01-15 01:13:44 +00:00
return Inertia::location(
Socialite::driver($this->driver)
->scopes($this->scopes)
->with([
'redirect_uri' => config('services.linkedin-openid.redirect_page'),
])
->redirect()
->getTargetUrl()
);
}
public function callback(Request $request): View|RedirectResponse
2026-01-15 01:13:44 +00:00
{
$workspaceId = session('social_connect_workspace');
if (! $workspaceId) {
return $this->popupCallback(false, __('accounts.popup_callback.session_expired'), $this->platform->value);
2026-01-15 01:13:44 +00:00
}
$workspace = Workspace::find($workspaceId);
2026-01-15 17:24:39 +00:00
if (! $workspace || ! $request->user()->can('manageAccounts', $workspace)) {
return $this->popupCallback(false, __('accounts.popup_callback.workspace_not_found'), $this->platform->value);
2026-01-15 01:13:44 +00:00
}
try {
$socialUser = Socialite::driver($this->driver)
->scopes($this->scopes)
->with([
'redirect_uri' => config('services.linkedin-openid.redirect_page'),
])
->user();
// Fetch organizations the user is admin of
$organizations = $this->fetchOrganizations($socialUser->token);
if (empty($organizations)) {
return $this->popupCallback(false, __('accounts.popup_callback.not_linkedin_admin'), $this->platform->value);
2026-01-15 01:13:44 +00:00
}
// Store data in session and redirect to selection page
session([
'linkedin_page_pending' => [
'workspace_id' => $workspace->id,
'user_id' => $socialUser->getId(),
'name' => $socialUser->getName(),
'avatar' => $socialUser->getAvatar(),
'token' => $socialUser->token,
'refresh_token' => $socialUser->refreshToken,
'expires_in' => $socialUser->expiresIn,
'approved_scopes' => $socialUser->approvedScopes ?? [],
2026-01-15 01:13:44 +00:00
'organizations' => $organizations,
'reconnect_id' => session('linkedin_page_reconnect_id'),
2026-01-15 01:13:44 +00:00
],
]);
return redirect()->route('app.social.linkedin-page.select-page');
2026-01-15 01:13:44 +00:00
} catch (\Exception $e) {
Log::error('LinkedIn Page OAuth Error', [
'error' => $e->getMessage(),
]);
return $this->popupCallback(false, __('accounts.popup_callback.error_connecting'), $this->platform->value);
2026-01-15 01:13:44 +00:00
}
}
public function selectPage(Request $request): Response|RedirectResponse
{
$pendingData = session('linkedin_page_pending');
if (! $pendingData) {
session()->flash('flash.banner', __('accounts.flash.session_expired'));
session()->flash('flash.bannerStyle', 'danger');
return redirect()->route('app.accounts');
2026-01-15 01:13:44 +00:00
}
$workspace = Workspace::find($pendingData['workspace_id']);
2026-01-15 17:24:39 +00:00
if (! $workspace || ! $request->user()->can('manageAccounts', $workspace)) {
session()->flash('flash.banner', __('accounts.flash.workspace_not_found'));
session()->flash('flash.bannerStyle', 'danger');
return redirect()->route('app.accounts');
2026-01-15 01:13:44 +00:00
}
return Inertia::render('accounts/LinkedInPageSelect', [
'workspace' => $workspace,
'organizations' => $pendingData['organizations'],
]);
}
public function select(Request $request): View
2026-01-15 01:13:44 +00:00
{
$request->validate([
'organization_id' => 'required',
'organization_name' => 'required|string',
'organization_vanity_name' => 'nullable|string',
'organization_logo' => 'nullable|string',
]);
$pendingData = session('linkedin_page_pending');
if (! $pendingData) {
return $this->popupCallback(false, __('accounts.popup_callback.session_expired'), $this->platform->value);
2026-01-15 01:13:44 +00:00
}
$workspace = Workspace::find($pendingData['workspace_id']);
2026-01-15 17:24:39 +00:00
if (! $workspace || ! $request->user()->can('manageAccounts', $workspace)) {
return $this->popupCallback(false, __('accounts.popup_callback.workspace_not_found'), $this->platform->value);
2026-01-15 01:13:44 +00:00
}
try {
$avatarPath = uploadFromUrl($request->organization_logo);
$reconnectId = $pendingData['reconnect_id'] ?? null;
if ($reconnectId) {
// Reconnect existing account
$existingAccount = $workspace->socialAccounts()->find($reconnectId);
if ($existingAccount) {
$existingAccount->update([
'platform_user_id' => $request->organization_id,
'username' => $request->organization_vanity_name,
'display_name' => $request->organization_name,
'avatar_url' => $avatarPath,
'access_token' => $pendingData['token'],
'refresh_token' => $pendingData['refresh_token'],
'token_expires_at' => $pendingData['expires_in'] ? now()->addSeconds($pendingData['expires_in']) : null,
// LinkedIn returns scope CSV-joined but Socialite splits on space, so re-split here.
'scopes' => explode(',', implode(',', $pendingData['approved_scopes'] ?? [])),
'meta' => [
'organization_id' => $request->organization_id,
'admin_user_id' => $pendingData['user_id'],
'admin_name' => $pendingData['name'],
],
]);
$existingAccount->markAsConnected();
// Sync tokens to LinkedIn personal if it exists
app(LinkedInTokenSynchronizer::class)->syncTokens($existingAccount);
session()->forget(['linkedin_page_pending', 'linkedin_page_reconnect_id']);
return $this->popupCallback(true, __('accounts.popup_callback.reconnected'), $this->platform->value);
}
}
2026-01-15 01:13:44 +00:00
$account = $workspace->socialAccounts()->updateOrCreate(
[
'platform' => $this->platform->value,
'platform_user_id' => $request->organization_id,
2026-01-15 01:13:44 +00:00
],
[
'username' => $request->organization_vanity_name,
'display_name' => $request->organization_name,
'avatar_url' => $avatarPath,
'access_token' => $pendingData['token'],
'refresh_token' => $pendingData['refresh_token'],
'token_expires_at' => $pendingData['expires_in'] ? now()->addSeconds($pendingData['expires_in']) : null,
// LinkedIn returns scope CSV-joined but Socialite splits on space, so re-split here.
'scopes' => explode(',', implode(',', $pendingData['approved_scopes'] ?? [])),
'status' => Status::Connected,
'error_message' => null,
'disconnected_at' => null,
'meta' => [
'organization_id' => $request->organization_id,
'admin_user_id' => $pendingData['user_id'],
'admin_name' => $pendingData['name'],
],
],
);
2026-01-15 01:13:44 +00:00
// Sync tokens to LinkedIn personal if it exists
app(LinkedInTokenSynchronizer::class)->syncTokens($account);
session()->forget(['linkedin_page_pending', 'linkedin_page_reconnect_id']);
2026-01-15 01:13:44 +00:00
return $this->popupCallback(true, __('accounts.popup_callback.connected'), $this->platform->value);
2026-01-15 01:13:44 +00:00
} catch (\Exception $e) {
Log::error('LinkedIn Page selection error', [
'error' => $e->getMessage(),
]);
return $this->popupCallback(false, __('accounts.popup_callback.error_connecting_page'), $this->platform->value);
2026-01-15 01:13:44 +00:00
}
}
private function fetchOrganizations(string $accessToken): array
{
$response = Http::withToken($accessToken)
->get(config('trypost.platforms.linkedin-page.api').'/v2/organizationAcls', [
2026-01-15 01:13:44 +00:00
'q' => 'roleAssignee',
'role' => 'ADMINISTRATOR',
'projection' => '(elements*(organization~(id,localizedName,vanityName,logoV2(original~:playableStreams))))',
]);
if ($response->failed()) {
Log::error('LinkedIn Organizations fetch error', [
'error' => $response->body(),
]);
return [];
}
$data = $response->json();
$organizations = [];
foreach (data_get($data, 'elements', []) as $element) {
$org = data_get($element, 'organization~', null);
2026-01-15 01:13:44 +00:00
if ($org) {
$logoUrl = null;
$logoUrl = data_get($org, 'logoV2.original~.elements.0.identifiers.0.identifier');
2026-01-15 01:13:44 +00:00
$organizations[] = [
'id' => data_get($org, 'id'),
'name' => data_get($org, 'localizedName', 'Unknown'),
'vanity_name' => data_get($org, 'vanityName', null),
2026-01-15 01:13:44 +00:00
'logo' => $logoUrl,
];
}
}
return $organizations;
}
}