From e704b1246ec8c66beadb11674892c59f63a8994d Mon Sep 17 00:00:00 2001 From: Daniel Covington Date: Thu, 17 Sep 2026 11:02:59 -0400 Subject: [PATCH] Add APP_DEBUG auth bypass for local development Skips Keycloak SSO entirely when APP_DEBUG=true, treating every request as an authenticated dev-admin user. Must stay false in any deployed environment (see .env_prod). Co-Authored-By: Claude Sonnet 5 --- app/Services/AuthService.php | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) diff --git a/app/Services/AuthService.php b/app/Services/AuthService.php index 330b962..0a680c7 100644 --- a/app/Services/AuthService.php +++ b/app/Services/AuthService.php @@ -9,6 +9,25 @@ use Stevenmaguire\OAuth2\Client\Provider\Keycloak; class AuthService { + /** + * When APP_DEBUG is true, auth is bypassed entirely and every request is + * treated as an already-authenticated dev user. Must be false in any + * deployed/production environment — see .env_prod. + */ + private static function debugBypass(): bool + { + return filter_var(getenv('APP_DEBUG'), FILTER_VALIDATE_BOOLEAN); + } + + private static function devUser(): array + { + return [ + 'preferred_username' => 'dev-admin', + 'email' => 'dev-admin@localhost', + 'name' => 'Dev Admin (APP_DEBUG bypass)', + ]; + } + private static function config(): array { static $config = null; @@ -59,6 +78,10 @@ class AuthService public static function requireLogin(): ?Response { + if (self::debugBypass()) { + return null; + } + if (!self::isLoggedIn()) { $_SESSION['auth_return_to'] = $_SERVER['REQUEST_URI'] ?? '/'; return Response::redirect('/auth/login'); @@ -69,11 +92,19 @@ class AuthService public static function isLoggedIn(): bool { + if (self::debugBypass()) { + return true; + } + return !empty($_SESSION['auth_user']); } public static function getCurrentUser(): array { + if (self::debugBypass() && empty($_SESSION['auth_user'])) { + return self::devUser(); + } + return $_SESSION['auth_user'] ?? []; }