- Config: auth, services, logging, queue and database only repeated the
framework's own files and are gone; the others keep only the keys that
differ (app version, cache serializable_classes, session cookie name,
Markdown mail theme, the shares disk, three Octane values, Livewire's
pagination theme and payload guards).
- Email verification is removed: User never implemented MustVerifyEmail,
so it was never enforced, and SealShare has a single admin and no
registration. CreateNewUser goes with it.
- FileEncryptionService::encryptFile() and generateSalt() were only used
by tests; tests build files with encryptTestFile() in tests/Pest.php.
- The expiration options are defined once, as Share::EXPIRATIONS. "30 Days"
now lasts 30 days instead of a calendar month, and Admin settings only
save a default expiration that is one of the options.
- One-caller helpers are inlined, the uploader reads chunk responses with
XHR's responseType, and starter-kit leftovers are removed.
- Docker: PHP reads the PHP_* limits from the environment itself
(${VAR:-default} in uploads.ini); both entrypoints stop writing the ini.
docker-compose.yml shares the app and scheduler variables through one
anchor. The dev image installs gd for the screenshot publisher and fake
test images.
- Development runs in Docker only: the composer dev script, concurrently,
laravel/pail, laravel/sail, autoprefixer and the shell-quote override
are gone.
- phpunit.xml forces the test environment with <server> entries, so tests
run in the dev container no longer use its real database.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
156 lines
5.1 KiB
PHP
156 lines
5.1 KiB
PHP
<?php
|
|
|
|
use Laravel\Fortify\Features;
|
|
|
|
return [
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Fortify Guard
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| Here you may specify which authentication guard Fortify will use while
|
|
| authenticating users. This value should correspond with one of your
|
|
| guards that is already present in your "auth" configuration file.
|
|
|
|
|
*/
|
|
|
|
'guard' => 'web',
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Fortify Password Broker
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| Here you may specify which password broker Fortify can use when a user
|
|
| is resetting their password. This configured value should match one
|
|
| of your password brokers setup in your "auth" configuration file.
|
|
|
|
|
*/
|
|
|
|
'passwords' => 'users',
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Username / Email
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| This value defines which model attribute should be considered as your
|
|
| application's "username" field. Typically, this might be the email
|
|
| address of the users but you are free to change this value here.
|
|
|
|
|
| Out of the box, Fortify expects forgot password and reset password
|
|
| requests to have a field named 'email'. If the application uses
|
|
| another name for the field you may define it below as needed.
|
|
|
|
|
*/
|
|
|
|
'username' => 'email',
|
|
|
|
'email' => 'email',
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Lowercase Usernames
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| This value defines whether usernames should be lowercased before saving
|
|
| them in the database, as some database system string fields are case
|
|
| sensitive. You may disable this for your application if necessary.
|
|
|
|
|
*/
|
|
|
|
'lowercase_usernames' => true,
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Home Path
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| Here you may configure the path where users will get redirected during
|
|
| authentication or password reset when the operations are successful
|
|
| and the user is authenticated. You are free to change this value.
|
|
|
|
|
*/
|
|
|
|
'home' => '/admin/dashboard',
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Fortify Routes Prefix / Subdomain
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| Here you may specify which prefix Fortify will assign to all the routes
|
|
| that it registers with the application. If necessary, you may change
|
|
| subdomain under which all of the Fortify routes will be available.
|
|
|
|
|
*/
|
|
|
|
'prefix' => '',
|
|
|
|
'domain' => null,
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Fortify Routes Middleware
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| Here you may specify which middleware Fortify will assign to the routes
|
|
| that it registers with the application. If necessary, you may change
|
|
| these middleware but typically this provided default is preferred.
|
|
|
|
|
*/
|
|
|
|
'middleware' => ['web'],
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Rate Limiting
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| By default, Fortify will throttle logins to five requests per minute for
|
|
| every email and IP address combination. However, if you would like to
|
|
| specify a custom rate limiter to call then you may specify it here.
|
|
|
|
|
*/
|
|
|
|
'limiters' => [
|
|
'login' => 'login',
|
|
'two-factor' => 'two-factor',
|
|
],
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Register View Routes
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| Here you may specify if the routes returning views should be disabled as
|
|
| you may not need them when building your own application. This may be
|
|
| especially true if you're writing a custom single-page application.
|
|
|
|
|
*/
|
|
|
|
'views' => true,
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Features
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| Some of the Fortify features are optional. You may disable the features
|
|
| by removing them from this array. You're free to only remove some of
|
|
| these features, or you can even remove all of these if you need to.
|
|
|
|
|
*/
|
|
|
|
'features' => [
|
|
Features::resetPasswords(),
|
|
Features::twoFactorAuthentication([
|
|
'confirm' => true,
|
|
'confirmPassword' => true,
|
|
// 'window' => 0
|
|
]),
|
|
],
|
|
|
|
];
|