Critical: - Fix EnsureUserSetupIsComplete middleware route name prefixes and redirect Subscription step to subscribe page (not onboarding) - Fix MCP session pollution: Auth::setUser() instead of Auth::login() - Remove dead BillingController::addWorkspace/removeWorkspace methods - Remove broken Workspace::pendingInvites() method Security (IDOR): - MediaController: add workspace ownership verification on all endpoints - UpdatePostRequest: scope label_ids validation to current workspace - UpdatePostRequest: scope platform IDs validation to current post Security (other): - Fix open redirect in login and registration (validate internal URLs) - Add validation to API PostController store/update (was $request->all()) - Prevent Owner role assignment via updateRole endpoint - Fix API post author attribution to use workspace owner Authorization: - PostController: use createPost policy instead of view for store/update/destroy Logic: - Post Status enum labels now use translation system instead of hardcoded Portuguese - Workspace deletion cleans up current_workspace_id for all affected members - StoreWorkspaceInviteRequest: replace Portuguese validation messages with __() Rename onboarding: - Step1.vue -> Role.vue, Step2.vue -> Connect.vue - Controller methods: step1->role, storeStep1->storeRole, step2->connect, storeStep2->storeConnect All 728 tests passing.
57 lines
1.8 KiB
PHP
57 lines
1.8 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Http\Middleware\App;
|
|
|
|
use App\Enums\User\Setup;
|
|
use Closure;
|
|
use Illuminate\Http\Request;
|
|
use Symfony\Component\HttpFoundation\Response;
|
|
|
|
class EnsureUserSetupIsComplete
|
|
{
|
|
/**
|
|
* Handle an incoming request.
|
|
*
|
|
* @param Closure(Request): (Response) $next
|
|
*/
|
|
public function handle(Request $request, Closure $next): Response
|
|
{
|
|
$user = $request->user();
|
|
|
|
if (! $user) {
|
|
return $next($request);
|
|
}
|
|
|
|
// If setup is completed, allow through
|
|
if ($user->setup === Setup::Completed) {
|
|
return $next($request);
|
|
}
|
|
|
|
// Map setup status to allowed routes
|
|
$allowedRoutes = match ($user->setup) {
|
|
Setup::Role => ['app.onboarding.role', 'app.onboarding.role.store'],
|
|
Setup::Connections => ['app.onboarding.connect', 'app.onboarding.connect.store', 'app.social.*'],
|
|
Setup::Subscription => ['app.subscribe', 'app.billing.*', 'app.onboarding.complete'],
|
|
default => ['app.onboarding.role', 'app.onboarding.role.store'],
|
|
};
|
|
|
|
$currentRoute = $request->route()?->getName();
|
|
|
|
// Check if current route is allowed
|
|
foreach ($allowedRoutes as $pattern) {
|
|
if ($currentRoute === $pattern || fnmatch($pattern, $currentRoute ?? '')) {
|
|
return $next($request);
|
|
}
|
|
}
|
|
|
|
// Redirect to appropriate step
|
|
return match ($user->setup) {
|
|
Setup::Role => redirect()->route('app.onboarding.role'),
|
|
Setup::Connections => redirect()->route('app.onboarding.connect'),
|
|
Setup::Subscription => redirect()->route('app.subscribe'),
|
|
default => redirect()->route('app.onboarding.role'),
|
|
};
|
|
}
|
|
}
|