Skips Keycloak SSO entirely when APP_DEBUG=true, treating every request as an authenticated dev-admin user. Must stay false in any deployed environment (see .env_prod). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>master
| @@ -9,6 +9,25 @@ use Stevenmaguire\OAuth2\Client\Provider\Keycloak; | |||||
| class AuthService | class AuthService | ||||
| { | { | ||||
| /** | |||||
| * When APP_DEBUG is true, auth is bypassed entirely and every request is | |||||
| * treated as an already-authenticated dev user. Must be false in any | |||||
| * deployed/production environment — see .env_prod. | |||||
| */ | |||||
| private static function debugBypass(): bool | |||||
| { | |||||
| return filter_var(getenv('APP_DEBUG'), FILTER_VALIDATE_BOOLEAN); | |||||
| } | |||||
| private static function devUser(): array | |||||
| { | |||||
| return [ | |||||
| 'preferred_username' => 'dev-admin', | |||||
| 'email' => 'dev-admin@localhost', | |||||
| 'name' => 'Dev Admin (APP_DEBUG bypass)', | |||||
| ]; | |||||
| } | |||||
| private static function config(): array | private static function config(): array | ||||
| { | { | ||||
| static $config = null; | static $config = null; | ||||
| @@ -59,6 +78,10 @@ class AuthService | |||||
| public static function requireLogin(): ?Response | public static function requireLogin(): ?Response | ||||
| { | { | ||||
| if (self::debugBypass()) { | |||||
| return null; | |||||
| } | |||||
| if (!self::isLoggedIn()) { | if (!self::isLoggedIn()) { | ||||
| $_SESSION['auth_return_to'] = $_SERVER['REQUEST_URI'] ?? '/'; | $_SESSION['auth_return_to'] = $_SERVER['REQUEST_URI'] ?? '/'; | ||||
| return Response::redirect('/auth/login'); | return Response::redirect('/auth/login'); | ||||
| @@ -69,11 +92,19 @@ class AuthService | |||||
| public static function isLoggedIn(): bool | public static function isLoggedIn(): bool | ||||
| { | { | ||||
| if (self::debugBypass()) { | |||||
| return true; | |||||
| } | |||||
| return !empty($_SESSION['auth_user']); | return !empty($_SESSION['auth_user']); | ||||
| } | } | ||||
| public static function getCurrentUser(): array | public static function getCurrentUser(): array | ||||
| { | { | ||||
| if (self::debugBypass() && empty($_SESSION['auth_user'])) { | |||||
| return self::devUser(); | |||||
| } | |||||
| return $_SESSION['auth_user'] ?? []; | return $_SESSION['auth_user'] ?? []; | ||||
| } | } | ||||
Powered by TurnKey Linux.