mirror of
https://github.com/coollabsio/coolify.git
synced 2026-09-27 17:55:59 -04:00
fix(auth): redirect authenticated stale-token login submissions to the dashboard
This commit is contained in:
@@ -3,7 +3,11 @@
|
||||
use App\Models\InstanceSettings;
|
||||
use App\Models\Team;
|
||||
use App\Models\User;
|
||||
use Illuminate\Contracts\Debug\ExceptionHandler;
|
||||
use Illuminate\Foundation\Testing\RefreshDatabase;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Session\TokenMismatchException;
|
||||
use Illuminate\Support\Facades\Route;
|
||||
|
||||
uses(RefreshDatabase::class);
|
||||
|
||||
@@ -78,3 +82,33 @@ it('renders 419 error page with login link instead of previous url', function ()
|
||||
expect($view)->toContain('error-shell');
|
||||
expect($view)->not->toContain('url()->previous()');
|
||||
});
|
||||
|
||||
it('redirects an authenticated stale two-factor submission home instead of showing 419', function () {
|
||||
$request = Request::create('/two-factor-challenge', 'POST');
|
||||
$request->setRouteResolver(fn () => Route::getRoutes()->match($request));
|
||||
$request->setUserResolver(fn () => $this->user);
|
||||
|
||||
$response = app(ExceptionHandler::class)->render($request, new TokenMismatchException('CSRF token mismatch.'));
|
||||
|
||||
expect($response->getStatusCode())->toBe(302)
|
||||
->and($response->headers->get('Location'))->toBe(url('/'));
|
||||
});
|
||||
|
||||
it('still returns 419 for a stale two-factor submission without an authenticated session', function () {
|
||||
$request = Request::create('/two-factor-challenge', 'POST');
|
||||
$request->setRouteResolver(fn () => Route::getRoutes()->match($request));
|
||||
|
||||
$response = app(ExceptionHandler::class)->render($request, new TokenMismatchException('CSRF token mismatch.'));
|
||||
|
||||
expect($response->getStatusCode())->toBe(419);
|
||||
});
|
||||
|
||||
it('keeps the 419 for stale tokens on routes other than login and the two-factor challenge', function () {
|
||||
$request = Request::create('/two-factor-challenge', 'GET');
|
||||
$request->setRouteResolver(fn () => Route::getRoutes()->match($request));
|
||||
$request->setUserResolver(fn () => $this->user);
|
||||
|
||||
$response = app(ExceptionHandler::class)->render($request, new TokenMismatchException('CSRF token mismatch.'));
|
||||
|
||||
expect($response->getStatusCode())->toBe(419);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user