Files
3dealer/bootstrap/app.php
T

51 lines
2.5 KiB
PHP
Raw Normal View History

2026-07-03 13:46:54 +00:00
<?php
use Illuminate\Foundation\Application;
use Illuminate\Foundation\Configuration\Exceptions;
use Illuminate\Foundation\Configuration\Middleware;
return Application::configure(basePath: dirname(__DIR__))
->withRouting(
web: __DIR__ . '/../routes/web.php',
commands: __DIR__ . '/../routes/console.php',
2026-07-03 13:46:54 +00:00
health: '/up',
)
->withMiddleware(function (Middleware $middleware): void {
// nginx (docker/nginx/prod.conf) only listens on plain HTTP:80.
// Without trusting that layer's X-Forwarded-Proto header, Laravel sees every
// request as http://, so url()/signed-route generation and
// verification (URL::hasValidSignature()) both use the wrong
// scheme — breaks any signed URL whose recipient hits it over
// https (e.g. Modules\Core\Shipping\Http\Controllers\
// DownloadShipmentLabelController's label links) with a 401.
// '*' trusts whatever's immediately upstream, since that's
// container-to-container inside the same deploy, not arbitrary
// public traffic.
$middleware->trustProxies(at: '*');
// Laravel's priority list would otherwise run `auth` before core's
// `locale` middleware, so the redirects below would build URLs before
// URL::defaults(['locale' => …]) is set, throwing a missing-parameter error.
$middleware->prependToPriorityList(
before: \Illuminate\Contracts\Auth\Middleware\AuthenticatesRequests::class,
prepend: \Modules\Core\Localization\Middleware\LocaleMiddleware::class,
);
// Both resolve inside the {locale} group, after the `locale` middleware
// has set URL::defaults(['locale' => …]), so route() needs no locale arg.
$middleware->redirectGuestsTo(fn() => route('login'));
$middleware->redirectUsersTo(fn() => route('home'));
// Core's session registry (Modules\Core\Auth\Services\
// UserSessionService) is enforcement-optional by design — see
// EnsureSessionNotRevoked's own docblock — and this app never
// wired it in. Without this, revokeAllSessions() only flips a DB
// flag that nothing checks per-request: a leaked/stolen session
// cookie keeps working even after being "revoked". Appended to
// `web` (runs after `auth` resolves the user, which it needs).
$middleware->appendToGroup('web', \Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked::class);
2026-07-03 13:46:54 +00:00
})
->withExceptions(function (Exceptions $exceptions): void {
//
})->create();