|
3 | 3 | namespace App\Http\Controllers\Auth; |
4 | 4 |
|
5 | 5 | use App\Http\Controllers\Controller; |
| 6 | +use App\Models\AuditLog; |
6 | 7 | use App\Models\User; |
7 | 8 | use Illuminate\Foundation\Auth\AuthenticatesUsers; |
| 9 | +use Illuminate\Http\RedirectResponse; |
8 | 10 | use Illuminate\Http\Request; |
9 | 11 | use Illuminate\Support\Facades\Hash; |
10 | 12 | use Illuminate\Support\Facades\Log; |
@@ -161,4 +163,60 @@ protected function attemptLogin(Request $request): bool |
161 | 163 | $remember |
162 | 164 | ); |
163 | 165 | } |
| 166 | + |
| 167 | + |
| 168 | + /** |
| 169 | + * Hook appelé APRES un login réussi (LDAP ou local). |
| 170 | + * |
| 171 | + * Crée une entrée dans le journal d'audit pour tracer la connexion. |
| 172 | + */ |
| 173 | + protected function authenticated(Request $request, User $user): void |
| 174 | + { |
| 175 | + try { |
| 176 | + AuditLog::query()->create([ |
| 177 | + 'description' => 'Login', |
| 178 | + 'subject_id' => $user->id, |
| 179 | + 'subject_type' => User::class, |
| 180 | + 'user_id' => $user->id, |
| 181 | + 'properties' => [ |
| 182 | + 'user_agent' => $request->userAgent(), |
| 183 | + 'method' => $request->method(), |
| 184 | + 'url' => $request->fullUrl(), |
| 185 | + ], |
| 186 | + 'host' => $request->ip(), |
| 187 | + ]); |
| 188 | + } catch (\Throwable $e) { |
| 189 | + Log::warning('Failed to create login audit log', ['error' => $e->getMessage()]); |
| 190 | + } |
| 191 | + } |
| 192 | + |
| 193 | + public function logout(Request $request): RedirectResponse |
| 194 | + { |
| 195 | + $userId = auth()->id(); |
| 196 | + |
| 197 | + $this->guard()->logout(); |
| 198 | + $request->session()->invalidate(); |
| 199 | + $request->session()->regenerateToken(); |
| 200 | + |
| 201 | + try { |
| 202 | + AuditLog::query()->create([ |
| 203 | + 'description' => 'Logout', |
| 204 | + 'subject_id' => $userId, |
| 205 | + 'subject_type' => User::class, |
| 206 | + 'user_id' => $userId, |
| 207 | + 'properties' => [ |
| 208 | + 'user_agent' => $request->userAgent(), |
| 209 | + 'method' => $request->method(), |
| 210 | + 'url' => $request->fullUrl(), |
| 211 | + ], |
| 212 | + 'host' => $request->ip(), |
| 213 | + ]); |
| 214 | + } catch (\Throwable $e) { |
| 215 | + Log::warning('Failed to create logout audit log', ['error' => $e->getMessage()]); |
| 216 | + } |
| 217 | + |
| 218 | + return $this->loggedOut($request) ?: redirect('/'); |
| 219 | + } |
| 220 | + |
| 221 | + |
164 | 222 | } |
0 commit comments