v1.0.0
This commit is contained in:
70
src/app/Livewire/Auth/Login.php
Normal file
70
src/app/Livewire/Auth/Login.php
Normal file
@@ -0,0 +1,70 @@
|
||||
<?php
|
||||
|
||||
namespace App\Livewire\Auth;
|
||||
|
||||
use App\Support\Settings;
|
||||
use Illuminate\Support\Facades\Auth;
|
||||
use Livewire\Attributes\Url;
|
||||
use Livewire\Component;
|
||||
|
||||
class Login extends Component
|
||||
{
|
||||
public string $username = '';
|
||||
|
||||
public string $password = '';
|
||||
|
||||
public ?string $error = null;
|
||||
|
||||
/**
|
||||
* Where to land after a successful login — e.g. set by the guest ticket
|
||||
* confirmation screen's "Zaloguj się" button so it can jump straight to
|
||||
* the just-created ticket instead of the user's default area.
|
||||
*/
|
||||
#[Url]
|
||||
public ?string $redirect = null;
|
||||
|
||||
public function submit(): void
|
||||
{
|
||||
$this->error = null;
|
||||
|
||||
$attribute = Settings::ldapUsernameAttribute();
|
||||
|
||||
// Local accounts (created with a password from the admin panel) don't
|
||||
// necessarily exist in LDAP under this attribute, so we also let the
|
||||
// provider fall back to matching by e-mail + local password.
|
||||
$ok = Auth::attempt([
|
||||
$attribute => $this->username,
|
||||
'password' => $this->password,
|
||||
'fallback' => ['email' => $this->username],
|
||||
]);
|
||||
|
||||
if (! $ok) {
|
||||
$this->error = 'Nieprawidłowa nazwa użytkownika lub hasło.';
|
||||
$this->password = '';
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
request()->session()->regenerate();
|
||||
|
||||
$this->redirect($this->safeRedirectTarget() ?? Auth::user()->defaultArea(), navigate: false);
|
||||
}
|
||||
|
||||
/**
|
||||
* Only follow the ?redirect= target when it's a same-app relative path —
|
||||
* never an absolute/external URL, to avoid it being abused as an open redirect.
|
||||
*/
|
||||
protected function safeRedirectTarget(): ?string
|
||||
{
|
||||
if (! $this->redirect || ! str_starts_with($this->redirect, '/') || str_starts_with($this->redirect, '//')) {
|
||||
return null;
|
||||
}
|
||||
|
||||
return $this->redirect;
|
||||
}
|
||||
|
||||
public function render()
|
||||
{
|
||||
return view('livewire.auth.login');
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user