Three verification methods (TOTP authenticator, email code, backup codes), trusted device management with 30-day expiry, role-based enforcement for super_admin and org_admin, admin reset capability, and full test coverage (46 tests). Modifies login flow to support MFA challenge/response with temporary session tokens stored in cache. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
58 lines
2.3 KiB
PHP
58 lines
2.3 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Http\Resources\Api\V1;
|
|
|
|
use App\Models\Person;
|
|
use App\Services\MfaService;
|
|
use Illuminate\Http\Request;
|
|
use Illuminate\Http\Resources\Json\JsonResource;
|
|
|
|
final class MeResource extends JsonResource
|
|
{
|
|
public function toArray(Request $request): array
|
|
{
|
|
return [
|
|
'id' => $this->id,
|
|
'first_name' => $this->first_name,
|
|
'last_name' => $this->last_name,
|
|
'full_name' => $this->full_name,
|
|
'date_of_birth' => $this->date_of_birth?->toDateString(),
|
|
'email' => $this->email,
|
|
'timezone' => $this->timezone,
|
|
'locale' => $this->locale,
|
|
'avatar' => $this->avatar,
|
|
'email_verified_at' => $this->email_verified_at?->toIso8601String(),
|
|
'organisations' => $this->whenLoaded('organisations', fn () =>
|
|
$this->organisations->map(fn ($org) => [
|
|
'id' => $org->id,
|
|
'name' => $org->name,
|
|
'slug' => $org->slug,
|
|
'role' => $org->pivot->role,
|
|
])
|
|
),
|
|
'app_roles' => $this->getRoleNames()->values()->all(),
|
|
'permissions' => $this->getAllPermissions()->pluck('name')->values()->all(),
|
|
'portal_events' => $this->whenLoaded('persons', fn () =>
|
|
$this->persons->map(fn (Person $person) => [
|
|
'event_id' => $person->event_id,
|
|
'event_name' => $person->event->name,
|
|
'event_slug' => $person->event->slug,
|
|
'organisation_name' => $person->event->organisation->name,
|
|
'person_id' => $person->id,
|
|
'person_status' => $person->status,
|
|
'start_date' => $person->event->start_date?->toDateString(),
|
|
'end_date' => $person->event->end_date?->toDateString(),
|
|
])
|
|
),
|
|
'mfa' => [
|
|
'enabled' => $this->mfa_enabled,
|
|
'method' => $this->mfa_method,
|
|
'confirmed_at' => $this->mfa_confirmed_at?->toIso8601String(),
|
|
'setup_required' => app(MfaService::class)->isMfaRequired($this->resource) && ! $this->mfa_enabled,
|
|
],
|
|
];
|
|
}
|
|
}
|