mirror of
https://github.com/coollabsio/coolify.git
synced 2026-10-06 14:07:37 -04:00
Add audit levels and record user, OAuth, DNS, notification, and settings changes while removing the obsolete scheduled job monitoring UI and services.
75 lines
2.7 KiB
PHP
75 lines
2.7 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Controllers;
|
|
|
|
use App\Models\OauthSetting;
|
|
use App\Services\Auth\OauthLoginService;
|
|
use Illuminate\Support\Facades\Log;
|
|
use Symfony\Component\HttpKernel\Exception\HttpException;
|
|
|
|
class OauthController extends Controller
|
|
{
|
|
public function redirect(string $provider)
|
|
{
|
|
$oauthSetting = $this->enabledProvider($provider);
|
|
$socialiteProvider = get_socialite_provider($oauthSetting->provider);
|
|
|
|
return $socialiteProvider->redirect();
|
|
}
|
|
|
|
public function callback(string $provider, OauthLoginService $oauthLoginService)
|
|
{
|
|
try {
|
|
$oauthSetting = $this->enabledProvider($provider);
|
|
$oauthUser = get_socialite_provider($oauthSetting->provider)->user();
|
|
$user = $oauthLoginService->login($oauthSetting->provider, $oauthUser, $oauthSetting);
|
|
|
|
$team = $user->resolveStoredTeam();
|
|
if (! $team && $user->teams()->count() === 0) {
|
|
$team = $user->recreate_personal_team();
|
|
}
|
|
if ($team) {
|
|
session(['currentTeam' => $user->currentTeam = $team]);
|
|
}
|
|
|
|
return redirect('/');
|
|
} catch (\Exception $e) {
|
|
$this->logCallbackFailure($provider, $e);
|
|
|
|
$errorCode = $e instanceof HttpException ? 'auth.failed' : 'auth.failed.callback';
|
|
|
|
return redirect()->route('login')->withErrors([__($errorCode)]);
|
|
}
|
|
}
|
|
|
|
private function logCallbackFailure(string $provider, \Throwable $exception): void
|
|
{
|
|
auditLog('auth.oauth.callback_failed', [
|
|
'provider' => $provider,
|
|
'exception_class' => $exception::class,
|
|
'reason' => $exception instanceof HttpException ? 'access_denied' : 'callback_error',
|
|
], 'warning');
|
|
Log::error('OAuth callback failed.', [
|
|
'provider' => $provider,
|
|
'exception_class' => $exception::class,
|
|
'exception_message' => $exception->getMessage(),
|
|
'request_error' => request()->query('error'),
|
|
'request_error_description' => request()->query('error_description'),
|
|
'has_code' => request()->query->has('code'),
|
|
'has_state' => request()->query->has('state'),
|
|
'ip' => request()->ip(),
|
|
'exception' => $exception,
|
|
]);
|
|
}
|
|
|
|
private function enabledProvider(string $provider): OauthSetting
|
|
{
|
|
$oauthSetting = OauthSetting::where('provider', $provider)->first();
|
|
if (! $oauthSetting || ! $oauthSetting->enabled || ! $oauthSetting->couldBeEnabled()) {
|
|
throw new HttpException(403, 'OAuth provider is not enabled');
|
|
}
|
|
|
|
return $oauthSetting;
|
|
}
|
|
}
|