withRouting( web: __DIR__ . '/../routes/web.php', commands: __DIR__ . '/../routes/console.php', health: '/up', ) ->withMiddleware(function (Middleware $middleware): void { // nginx (docker/nginx/prod.conf) only listens on plain HTTP:80. // Without trusting that layer's X-Forwarded-Proto header, Laravel sees every // request as http://, so url()/signed-route generation and // verification (URL::hasValidSignature()) both use the wrong // scheme — breaks any signed URL whose recipient hits it over // https (e.g. Modules\Core\Shipping\Http\Controllers\ // DownloadShipmentLabelController's label links) with a 401. // '*' trusts whatever's immediately upstream, since that's // container-to-container inside the same deploy, not arbitrary // public traffic. $middleware->trustProxies(at: '*'); // Laravel's priority list would otherwise run `auth` before core's // `locale` middleware, so the redirects below would build URLs before // URL::defaults(['locale' => …]) is set, throwing a missing-parameter error. $middleware->prependToPriorityList( before: \Illuminate\Contracts\Auth\Middleware\AuthenticatesRequests::class, prepend: \Modules\Core\Localization\Middleware\LocaleMiddleware::class, ); // Both resolve inside the {locale} group, after the `locale` middleware // has set URL::defaults(['locale' => …]), so route() needs no locale arg. $middleware->redirectGuestsTo(fn() => route('login')); $middleware->redirectUsersTo(fn() => route('home')); // Core's session registry (Modules\Core\Auth\Services\ // UserSessionService) is enforcement-optional by design — see // EnsureSessionNotRevoked's own docblock — and this app never // wired it in. Without this, revokeAllSessions() only flips a DB // flag that nothing checks per-request: a leaked/stolen session // cookie keeps working even after being "revoked". Appended to // `web` (runs after `auth` resolves the user, which it needs). $middleware->appendToGroup('web', \Modules\Core\Auth\Http\Middleware\EnsureSessionNotRevoked::class); }) ->withExceptions(function (Exceptions $exceptions): void { // })->create();