Skip to content

Commit

Permalink
Force redirection if accessing urls where being logged is required (#…
Browse files Browse the repository at this point in the history
  • Loading branch information
ildyria authored Jan 1, 2025
1 parent b9fb1e8 commit 0b6ac75
Show file tree
Hide file tree
Showing 3 changed files with 31 additions and 17 deletions.
7 changes: 6 additions & 1 deletion app/Http/Middleware/LoginRequired.php
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ class LoginRequired
{
public const ROOT = 'root';
public const ALBUM = 'album';
public const ALWAYS = 'always';

/**
* Handle an incoming request.
Expand All @@ -35,7 +36,7 @@ class LoginRequired
*/
public function handle(Request $request, \Closure $next, string $requiredStatus): mixed
{
if (in_array($requiredStatus, [self::ALBUM, self::ROOT], true) === false) {
if (in_array($requiredStatus, [self::ALBUM, self::ROOT, self::ALWAYS], true) === false) {
throw new LycheeInvalidArgumentException($requiredStatus . ' is not a valid login requirement.');
}

Expand All @@ -44,6 +45,10 @@ public function handle(Request $request, \Closure $next, string $requiredStatus)
return $next($request);
}

if ($requiredStatus === self::ALWAYS) {
return redirect()->route('gallery');
}

if (!Configs::getValueAsBool('login_required')) {
// Login is not required. Proceed.
return $next($request);
Expand Down
20 changes: 10 additions & 10 deletions routes/web_v2.php
Original file line number Diff line number Diff line change
Expand Up @@ -35,17 +35,17 @@
Route::get('/search/{albumId}', [VueController::class, 'view'])->middleware(['migration:complete']);
Route::get('/search/{albumId}/{photoId}', [VueController::class, 'view'])->middleware(['migration:complete']);

Route::get('/profile', [VueController::class, 'view'])->name('profile')->middleware(['migration:complete']);
Route::get('/users', [VueController::class, 'view'])->middleware(['migration:complete']);
Route::get('/sharing', [VueController::class, 'view'])->middleware(['migration:complete']);
Route::get('/jobs', [VueController::class, 'view'])->middleware(['migration:complete']);
Route::get('/profile', [VueController::class, 'view'])->name('profile')->middleware(['migration:complete', 'login_required:always']);
Route::get('/users', [VueController::class, 'view'])->middleware(['migration:complete', 'login_required:always']);
Route::get('/sharing', [VueController::class, 'view'])->middleware(['migration:complete', 'login_required:always']);
Route::get('/jobs', [VueController::class, 'view'])->middleware(['migration:complete', 'login_required:always']);
Route::get('/diagnostics', [VueController::class, 'view'])->middleware(['migration:complete']);
Route::get('/statistics', [VueController::class, 'view'])->middleware(['migration:complete']);
Route::get('/maintenance', [VueController::class, 'view'])->middleware(['migration:complete']);
Route::get('/users', [VueController::class, 'view'])->middleware(['migration:complete']);
Route::get('/settings', [VueController::class, 'view'])->middleware(['migration:complete']);
Route::get('/permissions', [VueController::class, 'view'])->middleware(['migration:complete']);
Route::get('/fixTree', [VueController::class, 'view'])->middleware(['migration:complete']);
Route::get('/statistics', [VueController::class, 'view'])->middleware(['migration:complete', 'login_required:always']);
Route::get('/maintenance', [VueController::class, 'view'])->middleware(['migration:complete', 'login_required:always']);
Route::get('/users', [VueController::class, 'view'])->middleware(['migration:complete', 'login_required:always']);
Route::get('/settings', [VueController::class, 'view'])->middleware(['migration:complete', 'login_required:always']);
Route::get('/permissions', [VueController::class, 'view'])->middleware(['migration:complete', 'login_required:always']);
Route::get('/fixTree', [VueController::class, 'view'])->middleware(['migration:complete', 'login_required:always']);

Route::match(['get', 'post'], '/migrate', [Admin\UpdateController::class, 'migrate'])
->name('migrate')
Expand Down
21 changes: 15 additions & 6 deletions tests/Feature_v2/PagesTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -20,13 +20,7 @@ public function testIndex(): void
{
collect([
'/',
'/settings',
'/diagnostics',
'/jobs',
'/sharing',
'/users',
'/maintenance',
'/profile',
'/gallery',
'/gallery/' . $this->album4->id,
'/gallery/' . $this->album4->id . '/' . $this->photo4->id,
Expand All @@ -44,6 +38,21 @@ public function testIndex(): void
});
}

public function testRedirect(): void
{
collect([
'/settings',
'/jobs',
'/sharing',
'/users',
'/maintenance',
'/profile',
])->each(function ($addr) {
$response = $this->get($addr);
$this->assertRedirect($response);
});
}

public function testVueCrash(): void
{
$response = $this->get('/gallery/1234567890');
Expand Down

0 comments on commit 0b6ac75

Please sign in to comment.