The Connect button on /settings/authentication pointed at the
auth.{provider}.redirect routes that live behind `guest` middleware,
so authenticated users were bounced to /app/home before reaching
Socialite. The OAuth callback also needed to handle two flows
(signup/login vs link to current user) but had no branch for the
second case — meaning a different-email GitHub account would have
been registered as a new user, logging the original session out.
Splits the flows by intent:
- New `app.authentication.connect-provider` route in the auth group,
handled by the settings controller (where it sits next to
disconnect-provider). Replaces the OAuth signup link as the
Connect button's target.
- Auth callbacks moved out of the guest group (still one URL per
provider, since OAuth apps only register one) and gain a single
Auth::check() branch that calls connectToCurrentUser().
- connectToCurrentUser() rejects if the provider id already belongs
to a different user; otherwise sets it on the current user and
redirects back to settings with a flash message.
61 lines
3.2 KiB
PHP
61 lines
3.2 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
use App\Http\Controllers\Auth\AcceptInviteController;
|
|
use App\Http\Controllers\Auth\AuthenticatedSessionController;
|
|
use App\Http\Controllers\Auth\EmailVerificationNotificationController;
|
|
use App\Http\Controllers\Auth\EmailVerificationPromptController;
|
|
use App\Http\Controllers\Auth\GitHubController;
|
|
use App\Http\Controllers\Auth\GoogleController;
|
|
use App\Http\Controllers\Auth\NewPasswordController;
|
|
use App\Http\Controllers\Auth\PasswordResetLinkController;
|
|
use App\Http\Controllers\Auth\RegisteredUserController;
|
|
use App\Http\Controllers\Auth\SignupSuccessController;
|
|
use App\Http\Controllers\Auth\VerifyEmailController;
|
|
use Illuminate\Support\Facades\Route;
|
|
|
|
Route::get('/invites/{invite}', [AcceptInviteController::class, 'show'])->name('app.invites.show');
|
|
|
|
Route::middleware(['guest'])->group(function () {
|
|
Route::get('/register', [RegisteredUserController::class, 'create'])->name('register');
|
|
Route::post('/register', [RegisteredUserController::class, 'store'])->name('register.store');
|
|
|
|
Route::get('/login', [AuthenticatedSessionController::class, 'create'])->name('login');
|
|
Route::post('/login', [AuthenticatedSessionController::class, 'store'])->name('login.store');
|
|
|
|
Route::get('/forgot-password', [PasswordResetLinkController::class, 'create'])->name('password.request');
|
|
Route::post('/forgot-password', [PasswordResetLinkController::class, 'store'])->name('password.email');
|
|
|
|
Route::get('/reset-password/{token}', [NewPasswordController::class, 'create'])->name('password.reset');
|
|
Route::post('/reset-password', [NewPasswordController::class, 'store'])->name('password.store');
|
|
|
|
Route::get('/auth/google/redirect', [GoogleController::class, 'redirect'])->name('auth.google.redirect');
|
|
Route::get('/auth/github/redirect', [GitHubController::class, 'redirect'])->name('auth.github.redirect');
|
|
});
|
|
|
|
// Callbacks must be reachable by both guests (signup/login flow) and
|
|
// authenticated users (connect-from-settings flow). Branching on
|
|
// `Auth::check()` inside the callback is safe because the redirect that
|
|
// initiated the round-trip enforces the right middleware.
|
|
Route::get('/auth/google/callback', [GoogleController::class, 'callback'])->name('auth.google.callback');
|
|
Route::get('/auth/github/callback', [GitHubController::class, 'callback'])->name('auth.github.callback');
|
|
|
|
Route::middleware(['auth'])->group(function () {
|
|
Route::get('/register/success', SignupSuccessController::class)->name('register.success');
|
|
|
|
Route::get('/verify-email', EmailVerificationPromptController::class)->name('verification.notice');
|
|
|
|
Route::get('/verify-email/{id}/{hash}', VerifyEmailController::class)
|
|
->middleware(['signed', 'throttle:6,1'])
|
|
->name('verification.verify');
|
|
|
|
Route::post('/email/verification-notification', [EmailVerificationNotificationController::class, 'store'])
|
|
->middleware('throttle:6,1')
|
|
->name('verification.send');
|
|
|
|
Route::post('/logout', [AuthenticatedSessionController::class, 'destroy'])->name('logout');
|
|
|
|
Route::post('/invites/{invite}/accept', [AcceptInviteController::class, 'accept'])->name('app.invites.accept');
|
|
Route::post('/invites/{invite}/decline', [AcceptInviteController::class, 'decline'])->name('app.invites.decline');
|
|
});
|