diff --git a/app/Services/AuthService.php b/app/Services/AuthService.php index 330b962..0a680c7 100644 --- a/app/Services/AuthService.php +++ b/app/Services/AuthService.php @@ -9,6 +9,25 @@ use Stevenmaguire\OAuth2\Client\Provider\Keycloak; class AuthService { + /** + * When APP_DEBUG is true, auth is bypassed entirely and every request is + * treated as an already-authenticated dev user. Must be false in any + * deployed/production environment — see .env_prod. + */ + private static function debugBypass(): bool + { + return filter_var(getenv('APP_DEBUG'), FILTER_VALIDATE_BOOLEAN); + } + + private static function devUser(): array + { + return [ + 'preferred_username' => 'dev-admin', + 'email' => 'dev-admin@localhost', + 'name' => 'Dev Admin (APP_DEBUG bypass)', + ]; + } + private static function config(): array { static $config = null; @@ -59,6 +78,10 @@ class AuthService public static function requireLogin(): ?Response { + if (self::debugBypass()) { + return null; + } + if (!self::isLoggedIn()) { $_SESSION['auth_return_to'] = $_SERVER['REQUEST_URI'] ?? '/'; return Response::redirect('/auth/login'); @@ -69,11 +92,19 @@ class AuthService public static function isLoggedIn(): bool { + if (self::debugBypass()) { + return true; + } + return !empty($_SESSION['auth_user']); } public static function getCurrentUser(): array { + if (self::debugBypass() && empty($_SESSION['auth_user'])) { + return self::devUser(); + } + return $_SESSION['auth_user'] ?? []; }