feature: remove change password for admin
This commit is contained in:
@@ -62,7 +62,7 @@ class AuthController extends Controller
|
||||
\Illuminate\Support\Facades\RateLimiter::clear($throttleKey);
|
||||
|
||||
$user = $result['user'];
|
||||
if ($user->first_login == \App\Models\User::FIRST_LOGIN_TRUE) {
|
||||
if ($user->role != \App\Models\User::ROLE_ADMIN && $user->first_login == \App\Models\User::FIRST_LOGIN_TRUE) {
|
||||
return redirect()->route('login')->with('dialog_first_login', true);
|
||||
}
|
||||
|
||||
|
||||
@@ -12,7 +12,7 @@ class ForceChangePasswordMiddleware
|
||||
{
|
||||
public function handle(Request $request, Closure $next): Response
|
||||
{
|
||||
if (Auth::check() && Auth::user()->first_login == User::FIRST_LOGIN_TRUE) {
|
||||
if (Auth::check() && Auth::user()->role != User::ROLE_ADMIN && Auth::user()->first_login == User::FIRST_LOGIN_TRUE) {
|
||||
if (!$request->routeIs('user.change_password') && !$request->routeIs('user.update_password') && !$request->routeIs('logout')) {
|
||||
return redirect()->route('user.change_password');
|
||||
}
|
||||
|
||||
@@ -92,7 +92,7 @@ class AdminService implements AdminServiceInterface
|
||||
'status' => User::STATUS_ACTIVE,
|
||||
'card' => 0,
|
||||
'flag_send' => User::FLAG_SEND_DISABLED,
|
||||
'first_login' => User::FIRST_LOGIN_TRUE,
|
||||
'first_login' => $data['role'] == User::ROLE_ADMIN ? User::FIRST_LOGIN_FALSE : User::FIRST_LOGIN_TRUE,
|
||||
]);
|
||||
}
|
||||
|
||||
|
||||
@@ -37,14 +37,14 @@ class AuthService implements AuthServiceInterface
|
||||
|
||||
public function getRedirectRouteForUser(User $user): string
|
||||
{
|
||||
if ($user->first_login == User::FIRST_LOGIN_TRUE) {
|
||||
return route('user.change_password');
|
||||
}
|
||||
|
||||
if ($user->role == User::ROLE_ADMIN) {
|
||||
return route('admin.dashboard');
|
||||
}
|
||||
|
||||
if ($user->first_login == User::FIRST_LOGIN_TRUE) {
|
||||
return route('user.change_password');
|
||||
}
|
||||
|
||||
return route('user.dashboard');
|
||||
}
|
||||
}
|
||||
@@ -197,6 +197,31 @@ class LoginNotificationTest extends TestCase
|
||||
$this->assertTrue(\Illuminate\Support\Facades\Auth::check());
|
||||
}
|
||||
|
||||
public function test_admin_first_login_does_not_redirect_to_change_password(): void
|
||||
{
|
||||
$admin = User::create([
|
||||
'msnv' => 5007,
|
||||
'name' => 'First Login Admin',
|
||||
'mail' => 'first_admin@example.com',
|
||||
'pass' => md5('password123'),
|
||||
'departments' => 1,
|
||||
'role' => User::ROLE_ADMIN,
|
||||
'status' => User::STATUS_ACTIVE,
|
||||
'card' => 10,
|
||||
'flag_send' => User::FLAG_SEND_ENABLED,
|
||||
'first_login' => User::FIRST_LOGIN_TRUE,
|
||||
]);
|
||||
|
||||
$response = $this->post('/login', [
|
||||
'mail' => 'first_admin@example.com',
|
||||
'password' => 'password123',
|
||||
]);
|
||||
|
||||
$response->assertRedirect(route('admin.dashboard'));
|
||||
$response->assertSessionMissing('dialog_first_login');
|
||||
$this->assertTrue(\Illuminate\Support\Facades\Auth::check());
|
||||
}
|
||||
|
||||
/**
|
||||
* Test Case 6: Brute-force protection
|
||||
*/
|
||||
|
||||
Reference in New Issue
Block a user