feature
This commit is contained in:
@@ -12,21 +12,42 @@ return Application::configure(basePath: dirname(__DIR__))
|
||||
// Implant C2: no CSRF / session
|
||||
require __DIR__.'/../routes/c2.php';
|
||||
|
||||
// Admin UI: session + CSRF
|
||||
// External webhooks (no CSRF)
|
||||
require __DIR__.'/../routes/hooks.php';
|
||||
|
||||
// Admin + agent UI: session + CSRF
|
||||
Route::middleware('web')->group(base_path('routes/admin.php'));
|
||||
Route::middleware('web')->group(base_path('routes/user.php'));
|
||||
},
|
||||
commands: __DIR__.'/../routes/console.php',
|
||||
health: '/up',
|
||||
)
|
||||
->withMiddleware(function (Middleware $middleware): void {
|
||||
$middleware->alias([
|
||||
'admin.super' => \App\Http\Middleware\EnsureSuperAdmin::class,
|
||||
]);
|
||||
|
||||
$middleware->validateCsrfTokens(except: [
|
||||
'api/*',
|
||||
'link/*',
|
||||
'hooks/*',
|
||||
]);
|
||||
|
||||
// Admin uses auth:admin; there is no default "login" route.
|
||||
$middleware->redirectGuestsTo(fn () => route('admin.login'));
|
||||
$middleware->redirectUsersTo(fn () => route('admin.home'));
|
||||
$middleware->redirectGuestsTo(function () {
|
||||
$path = request()->path();
|
||||
if (str_starts_with($path, 'user')) {
|
||||
return route('user.login');
|
||||
}
|
||||
|
||||
return route('admin.login');
|
||||
});
|
||||
$middleware->redirectUsersTo(function () {
|
||||
if (auth('agent')->check()) {
|
||||
return route('user.home');
|
||||
}
|
||||
|
||||
return route('admin.home');
|
||||
});
|
||||
})
|
||||
->withExceptions(function (Exceptions $exceptions): void {
|
||||
//
|
||||
|
||||
Reference in New Issue
Block a user