The Connect button on /settings/authentication pointed at the
auth.{provider}.redirect routes that live behind `guest` middleware,
so authenticated users were bounced to /app/home before reaching
Socialite. The OAuth callback also needed to handle two flows
(signup/login vs link to current user) but had no branch for the
second case — meaning a different-email GitHub account would have
been registered as a new user, logging the original session out.
Splits the flows by intent:
- New `app.authentication.connect-provider` route in the auth group,
handled by the settings controller (where it sits next to
disconnect-provider). Replaces the OAuth signup link as the
Connect button's target.
- Auth callbacks moved out of the guest group (still one URL per
provider, since OAuth apps only register one) and gain a single
Auth::check() branch that calls connectToCurrentUser().
- connectToCurrentUser() rejects if the provider id already belongs
to a different user; otherwise sets it on the current user and
redirects back to settings with a flash message.
115 lines
3.5 KiB
PHP
115 lines
3.5 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Http\Controllers\Auth;
|
|
|
|
use App\Actions\User\CreateUser;
|
|
use App\Http\Controllers\Auth\Concerns\PreservesUtmParameters;
|
|
use App\Http\Controllers\Controller;
|
|
use App\Models\User;
|
|
use Illuminate\Auth\Events\Registered;
|
|
use Illuminate\Http\RedirectResponse;
|
|
use Illuminate\Http\Request;
|
|
use Illuminate\Support\Facades\Auth;
|
|
use Laravel\Socialite\Facades\Socialite;
|
|
|
|
class GitHubController extends Controller
|
|
{
|
|
use PreservesUtmParameters;
|
|
|
|
public function redirect(Request $request): RedirectResponse
|
|
{
|
|
$this->storeUtmParameters($request);
|
|
|
|
return Socialite::driver('github')
|
|
->scopes(['read:user', 'user:email'])
|
|
->redirect();
|
|
}
|
|
|
|
public function callback(): RedirectResponse
|
|
{
|
|
try {
|
|
$githubUser = Socialite::driver('github')->user();
|
|
} catch (\Exception) {
|
|
return redirect()->route('login');
|
|
}
|
|
|
|
if (Auth::check()) {
|
|
return $this->connectToCurrentUser(Auth::user(), (string) $githubUser->getId());
|
|
}
|
|
|
|
$user = User::where('github_id', (string) $githubUser->getId())
|
|
->when($githubUser->getEmail(), fn ($query, $email) => $query->orWhere('email', $email))
|
|
->first();
|
|
|
|
if ($user) {
|
|
return $this->loginExistingUser($user, (string) $githubUser->getId());
|
|
}
|
|
|
|
if (! $githubUser->getEmail()) {
|
|
return redirect()->route('login')->withErrors([
|
|
'email' => __('auth.github_email_unavailable'),
|
|
]);
|
|
}
|
|
|
|
return $this->registerNewUser($githubUser);
|
|
}
|
|
|
|
private function connectToCurrentUser(User $user, string $githubId): RedirectResponse
|
|
{
|
|
$existing = User::where('github_id', $githubId)
|
|
->where('id', '!=', $user->id)
|
|
->first();
|
|
|
|
if ($existing) {
|
|
return redirect()->route('app.authentication.edit')
|
|
->with('flash.error', __('settings.authentication.providers.flash_already_linked', ['provider' => 'GitHub']));
|
|
}
|
|
|
|
if ($user->github_id !== $githubId) {
|
|
$user->update(['github_id' => $githubId]);
|
|
}
|
|
|
|
return redirect()->route('app.authentication.edit')
|
|
->with('flash.success', __('settings.authentication.providers.flash_connected', ['provider' => 'GitHub']));
|
|
}
|
|
|
|
private function loginExistingUser(User $user, string $githubId): RedirectResponse
|
|
{
|
|
if (! $user->github_id) {
|
|
$user->update(['github_id' => $githubId]);
|
|
}
|
|
|
|
if (! $user->hasVerifiedEmail()) {
|
|
$user->markEmailAsVerified();
|
|
}
|
|
|
|
Auth::login($user, remember: true);
|
|
|
|
$this->retrieveUtmParameters();
|
|
|
|
return redirect()->route('app.home');
|
|
}
|
|
|
|
private function registerNewUser(\Laravel\Socialite\Contracts\User $githubUser): RedirectResponse
|
|
{
|
|
$utmParameters = $this->retrieveUtmParameters();
|
|
|
|
$user = CreateUser::execute([
|
|
'name' => $githubUser->getName() ?? $githubUser->getNickname() ?? explode('@', $githubUser->getEmail())[0],
|
|
'email' => $githubUser->getEmail(),
|
|
'github_id' => (string) $githubUser->getId(),
|
|
'email_verified_at' => now(),
|
|
'registration_ip' => request()->ip(),
|
|
], $utmParameters);
|
|
|
|
event(new Registered($user));
|
|
|
|
Auth::login($user, remember: true);
|
|
|
|
session()->flash('auth_provider', 'github');
|
|
|
|
return redirect()->route('register.success', $utmParameters);
|
|
}
|
|
}
|