ifnex/04_Laravel/bootstrap/app.php
Kazem Alghasi 0209b6b32e feat(commitment-forms): implement end-to-end management and secure file access
Integrate a complete workflow for commitment forms including secure template downloads, customer uploads via WordPress AJAX, and administrative verification with automated notifications.

- Implement `downloadTemplate` and `downloadSigned` logic in `CommitmentFormController` to replace public symlinks with ownership-verified routes.
- Add `CommitmentFormVerifiedNotification` and `CommitmentFormRejectedNotification` to alert customers of status changes.
- Enhance WordPress bridge with AJAX-driven form listing, status badges, and upload capabilities.
- Update Filament `CommitmentFormsRelationManager` to provide better visibility into form directions and descriptions while restricting status edits to specific actions.
- Refactor Laravel 11 bootstrap configuration to handle guest redirection for API and web routes correctly.
- Add administrative controllers for secure file access within the admin panel.
2026-10-03 05:58:59 +03:30

65 lines
3.1 KiB
PHP
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<?php
use App\Http\Middleware\ApiKeyAuth;
use Illuminate\Auth\AuthenticationException;
use Illuminate\Foundation\Application;
use Illuminate\Foundation\Configuration\Exceptions;
use Illuminate\Foundation\Configuration\Middleware;
use Illuminate\Http\Request;
return Application::configure(basePath: dirname(__DIR__))
->withRouting(
web: __DIR__.'/../routes/web.php',
api: __DIR__.'/../routes/api.php',
commands: __DIR__.'/../routes/console.php',
health: '/up',
)
->withCommands([
\App\Console\Commands\ImportShippingRates::class,
\App\Console\Commands\ImportTrackingData::class,
\App\Console\Commands\UpdateExchangeRates::class,
\App\Console\Commands\GenerateApiToken::class,
\App\Console\Commands\SyncWordPressUsers::class,
])
->withMiddleware(function (Middleware $middleware): void {
$middleware->alias([
'api_key' => ApiKeyAuth::class,
]);
// پیش‌فرض لاراول ۱۱ مهمان‌ها را به route('login') می‌فرستد که در این پروژه وجود ندارد
// و باعث 500 می‌شود؛ با null، AuthenticationException به هندلر exceptions می‌رسد
// و برای api/* پاسخ JSON 401 برگردانده می‌شود.
$middleware->redirectGuestsTo(fn () => null);
// Stateful API برای Sanctum
$middleware->statefulApi();
// API با CORS
$middleware->api(prepend: \Illuminate\Http\Middleware\HandleCors::class);
// گروه web برای Filament و صفحات عادی
$middleware->group('web', [
\Illuminate\Cookie\Middleware\EncryptCookies::class,
\Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class,
\Illuminate\Session\Middleware\StartSession::class,
\Illuminate\View\Middleware\ShareErrorsFromSession::class,
\Illuminate\Foundation\Http\Middleware\ValidateCsrfToken::class,
\Illuminate\Routing\Middleware\SubstituteBindings::class,
]);
})
->withExceptions(function (Exceptions $exceptions): void {
// برای API‌ها، به جای redirect به login، JSON 401 برگردان
$exceptions->render(function (AuthenticationException $e, Request $request) {
if ($request->is('api/*') || $request->expectsJson() || $request->wantsJson()) {
return response()->json([
'success' => false,
'message' => 'Unauthenticated',
'error' => 'توکن نامعتبر است یا منقضی شده است. لطفاً دوباره وارد شوید.',
], 401);
}
// مهمان‌های وب (مثلاً بازکردن مستقیم روت‌های دانلود ادمین) به ورود پنل هدایت شوند —
// هندلر پیش‌فرض لاراول به route('login') می‌رود که در این پروژه وجود ندارد
return redirect()->guest(route('filament.admin.auth.login'));
});
})->create();