Files
servicedesk/src/app/Livewire/Auth/Login.php
Kacper 4e8f17189a
All checks were successful
Build and push image / build (push) Successful in 1m24s
v1.0.2
- Fix CI registry login (unauthorized): use dedicated REGISTRY_TOKEN secret
  instead of GITHUB_TOKEN, fail fast with a clear error if it's unset.
- Pause ticket work-timer while a ticket is closed (won't auto-start on open
  or manual resume; stops on close via status change, quick action, API, or
  merge).
- Reject empty/blank login submissions client- and server-side instead of
  passing them straight to the auth provider.
- Closing a ticket now sends only the "ticket closed" notification instead
  of also sending a duplicate "status changed" one.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-22 08:50:03 +02:00

81 lines
2.4 KiB
PHP

<?php
namespace App\Livewire\Auth;
use App\Support\Settings;
use Illuminate\Support\Facades\Auth;
use Livewire\Attributes\Url;
use Livewire\Component;
class Login extends Component
{
public string $username = '';
public string $password = '';
public ?string $error = null;
/**
* Where to land after a successful login — e.g. set by the guest ticket
* confirmation screen's "Zaloguj się" button so it can jump straight to
* the just-created ticket instead of the user's default area.
*/
#[Url]
public ?string $redirect = null;
public function submit(): void
{
$this->error = null;
// The form also has HTML `required` attributes so the browser blocks
// an empty submit before it ever reaches here, but that's only a UX
// nicety — nothing stops a request hitting this method directly, so
// it needs to fail closed on its own too.
if (trim($this->username) === '' || $this->password === '') {
$this->error = 'Podaj nazwę użytkownika i hasło.';
return;
}
$attribute = Settings::ldapUsernameAttribute();
// Local accounts (created with a password from the admin panel) don't
// necessarily exist in LDAP under this attribute, so we also let the
// provider fall back to matching by e-mail + local password.
$ok = Auth::attempt([
$attribute => $this->username,
'password' => $this->password,
'fallback' => ['email' => $this->username],
]);
if (! $ok) {
$this->error = 'Nieprawidłowa nazwa użytkownika lub hasło.';
$this->password = '';
return;
}
request()->session()->regenerate();
$this->redirect($this->safeRedirectTarget() ?? Auth::user()->defaultArea(), navigate: false);
}
/**
* Only follow the ?redirect= target when it's a same-app relative path —
* never an absolute/external URL, to avoid it being abused as an open redirect.
*/
protected function safeRedirectTarget(): ?string
{
if (! $this->redirect || ! str_starts_with($this->redirect, '/') || str_starts_with($this->redirect, '//')) {
return null;
}
return $this->redirect;
}
public function render()
{
return view('livewire.auth.login');
}
}