This commit is contained in:
Dan Harrin
2025-05-10 14:37:29 +01:00
parent 88330ec8b4
commit 097633a8e4
5 changed files with 25 additions and 23 deletions
@@ -32,13 +32,15 @@ return [
'notifications' => [
'sent' => [
'body' => 'If your account doesn\'t exist, you will not receive the email.',
],
'throttled' => [
'title' => 'Too many requests',
'body' => 'Please try again in :seconds seconds.',
],
'sent' => 'If that email address is valid in our records, we will send you an email to reset your password.',
],
];
@@ -63,16 +63,19 @@ class RequestPasswordReset extends SimplePage
$status = Password::broker(Filament::getAuthPasswordBroker())->sendResetLink(
$this->getCredentialsFromFormData($data),
function (CanResetPassword $user, string $token): void {
if (
($user instanceof FilamentUser) &&
(! $user->canAccessPanel(Filament::getCurrentPanel()))
) {
return;
}
if (! method_exists($user, 'notify')) {
$userClass = $user::class;
throw new Exception("Model [{$userClass}] does not have a [notify()] method.");
}
if (! ($user instanceof FilamentUser) || ! $user->canAccessPanel(Filament::getCurrentPanel())) {
return;
}
$notification = app(ResetPasswordNotification::class, ['token' => $token]);
$notification->url = Filament::getResetPasswordUrl($token, $user);
@@ -86,7 +89,7 @@ class RequestPasswordReset extends SimplePage
return;
}
$this->getSentNotification('filament-panels::pages/auth/password-reset/request-password-reset.notifications.sent')?->send();
$this->getSentNotification($status)?->send();
$this->form->fill();
}
@@ -116,6 +119,7 @@ class RequestPasswordReset extends SimplePage
{
return Notification::make()
->title(__($status))
->body(($status === Password::RESET_LINK_SENT) ? __('filament-panels::pages/auth/password-reset/request-password-reset.notifications.sent.body') : null)
->success();
}
@@ -82,8 +82,10 @@ class ResetPassword extends SimplePage
$status = Password::broker(Filament::getAuthPasswordBroker())->reset(
$this->getCredentialsFromFormData($data),
function (CanResetPassword | Model | Authenticatable $user) use ($data, &$hasPanelAccess) {
if (! ($user instanceof FilamentUser) || ! $user->canAccessPanel(Filament::getCurrentPanel())) {
if (
($user instanceof FilamentUser) &&
(! $user->canAccessPanel(Filament::getCurrentPanel()))
) {
$hasPanelAccess = false;
return;
@@ -4,7 +4,6 @@ use Filament\Facades\Filament;
use Filament\Notifications\Auth\ResetPassword;
use Filament\Notifications\Notification as FilamentNotification;
use Filament\Pages\Auth\PasswordReset\RequestPasswordReset;
use Filament\Panel;
use Filament\Tests\Models\User;
use Filament\Tests\TestCase;
use Illuminate\Support\Facades\Notification;
@@ -44,23 +43,21 @@ it('can request password reset', function () {
->assertNotified(
FilamentNotification::make()
->success()
->title(__('filament-panels::pages/auth/password-reset/request-password-reset.notifications.sent'))
->title(__('passwords.sent'))
->body(__('filament-panels::pages/auth/password-reset/request-password-reset.notifications.sent.body'))
);
Notification::assertSentTo($userToResetPassword, ResetPassword::class);
});
it('can gate password resets based on panel access', function () {
it('cannot request password reset without panel access', function () {
Notification::fake();
$this->assertGuest();
$userToResetPassword = User::factory()->create();
$testPanel = Panel::make();
$testPanel->id('test');
Filament::setCurrentPanel($testPanel);
Filament::setCurrentPanel(Filament::getPanel('custom'));
livewire(RequestPasswordReset::class)
->fillForm([
@@ -70,7 +67,8 @@ it('can gate password resets based on panel access', function () {
->assertNotified(
FilamentNotification::make()
->success()
->title(__('filament-panels::pages/auth/password-reset/request-password-reset.notifications.sent'))
->title(__('passwords.sent'))
->body(__('filament-panels::pages/auth/password-reset/request-password-reset.notifications.sent.body'))
);
Notification::assertNotSentTo($userToResetPassword, ResetPassword::class);
@@ -3,7 +3,6 @@
use Filament\Facades\Filament;
use Filament\Notifications\Notification;
use Filament\Pages\Auth\PasswordReset\ResetPassword;
use Filament\Panel;
use Filament\Tests\Models\User;
use Filament\Tests\TestCase;
use Illuminate\Auth\Events\PasswordReset;
@@ -75,7 +74,7 @@ it('can reset password', function () {
]);
});
it('can gate reset password based on panel access', function () {
it('cannot reset password without panel access', function () {
Event::fake();
$this->assertGuest();
@@ -83,10 +82,7 @@ it('can gate reset password based on panel access', function () {
$userToResetPassword = User::factory()->create();
$token = Password::createToken($userToResetPassword);
$testPanel = Panel::make();
$testPanel->id('test');
Filament::setCurrentPanel($testPanel);
Filament::setCurrentPanel(Filament::getPanel('custom'));
livewire(ResetPassword::class, [
'email' => $userToResetPassword->email,