[5.x] Ability to disable CP authentication - #8960

Merged
jasonvarga merged 25 commits into
5.xfrom
pr/7617
Jun 27, 2024
Merged

[5.x] Ability to disable CP authentication#8960
jasonvarga merged 25 commits into
5.xfrom
pr/7617

Conversation

@duncanmcclean

@duncanmccleanduncanmcclean commented Nov 9, 2023

Copy link
Copy Markdown
Member

This pull request implements a new config option, allowing developers to disable the Control Panel authentication pages.

Often times, if you're using something like Jetstream or Laravel Nova which provide their own login pages then you don't want an additional login page for users to somehow find their way to.

Authentication can be disabled by toggling the statamic.cp.auth.enabled option. You may optionally specify a URL for users to be redirected to instead:

<?php/*|--------------------------------------------------------------------------| Authentication|--------------------------------------------------------------------------|| Whether the Control Panel's authentication pages should be enabled,| or if users should be redirected elsewhere.|*/'auth' => [
'enabled' => false,
'redirect_to' => '/nova',
],

This PR replaces my previous PR, #7617.

@duncanmcclean
duncanmcclean marked this pull request as draft November 9, 2023 11:37
@duncanmcclean
duncanmcclean marked this pull request as ready for review November 9, 2023 12:07
Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

Copy link
Copy Markdown

Is this planned for 4.X? We would use this in almost all our apps that have a Statamic installation.

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

Sorry, we don't have an ETA for reviewing/merging this pull request. We'll get to it when we can.

In the meantime, you can pull this PR into your project with a composer patch.

@DwainsWorld

Copy link
Copy Markdown

No problem. Thanks for the update and the composer patch package link - very useful!

@DwainsWorld

Copy link
Copy Markdown

@duncanmcclean

I was giving this a try with composer patch, all went well. Except, within routes/cp.php:

Shouldn't this:

if (config('statamic.cp.auth', true)) {

Be:

if (config('statamic.cp.auth.enabled', true)) {

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

@DwainsWorld Yes, it should be, thanks! I've updated this PR.

@edalzell

Copy link
Copy Markdown
Contributor

This works great for me, thanks Duncan!

Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

DwainsWorld commented May 9, 2024

Copy link
Copy Markdown

Is anyone being hit with a 404 with this PR when attempting to "Resume your session"? Is it possible to disable the ability to resume and auto logout instead?

image
image

@edalzell

Copy link
Copy Markdown
Contributor

Yes, I've run into this. This flow needs to be reconsidered when CP login is disabled. We use it in a passwordless login situation so this part makes no sense, it should log out and redirect to the appropriate page.

@duncanmccleanduncanmcclean changed the title [4.x] Ability to disable CP authentication[5.x] Ability to disable CP authenticationMay 13, 2024
@duncanmcclean
duncanmcclean changed the base branch from 4.x to 5.xMay 13, 2024 10:30
duncanmccleanand others added 6 commits May 13, 2024 12:24
# Conflicts:
#	tests/Tags/User/ForgotPasswordFormTest.php
#	tests/Tags/User/LoginFormTest.php
#	tests/Tags/User/PasswordFormTest.php
#	tests/Tags/User/RegisterFormTest.php
Instead, redirect when there's an actual 401.
Apparently it's not completely accurate. You could get a few requests that return zero. It's fine for controlling when the modal pops up, but not a redirect. If you redirect, when you hit the login page your session will be extended, keeping you logged in.
@jasonvarga
jasonvarga merged commit 7ace3c1 into 5.xJun 27, 2024
@jasonvarga
jasonvarga deleted the pr/7617 branch June 27, 2024 20:01
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
* Allow configuring the Stache's Cache Store
Related: statamic/cms#10303
* Ability to disable CP authentication
Related: statamic/cms#8960
* Display custom logo as plain text
Related: statamic/cms#10350
* Track sites.yaml path in git integration config
Related: statamic/cms#10463
* Add ability to specify the queue connection on static:warm command
Related: statamic/cms#8634
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@duncanmcclean@DwainsWorld@edalzell@ryanmitchell@jasonvarga
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[5.x] Ability to disable CP authentication - #8960

Merged
jasonvarga merged 25 commits into
5.xfrom
pr/7617
Jun 27, 2024
Merged

[5.x] Ability to disable CP authentication#8960
jasonvarga merged 25 commits into
5.xfrom
pr/7617

Conversation

@duncanmcclean

@duncanmccleanduncanmcclean commented Nov 9, 2023

Copy link
Copy Markdown
Member

This pull request implements a new config option, allowing developers to disable the Control Panel authentication pages.

Often times, if you're using something like Jetstream or Laravel Nova which provide their own login pages then you don't want an additional login page for users to somehow find their way to.

Authentication can be disabled by toggling the statamic.cp.auth.enabled option. You may optionally specify a URL for users to be redirected to instead:

<?php/*|--------------------------------------------------------------------------| Authentication|--------------------------------------------------------------------------|| Whether the Control Panel's authentication pages should be enabled,| or if users should be redirected elsewhere.|*/'auth' => [
'enabled' => false,
'redirect_to' => '/nova',
],

This PR replaces my previous PR, #7617.

@duncanmcclean
duncanmcclean marked this pull request as draft November 9, 2023 11:37
@duncanmcclean
duncanmcclean marked this pull request as ready for review November 9, 2023 12:07
Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

Copy link
Copy Markdown

Is this planned for 4.X? We would use this in almost all our apps that have a Statamic installation.

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

Sorry, we don't have an ETA for reviewing/merging this pull request. We'll get to it when we can.

In the meantime, you can pull this PR into your project with a composer patch.

@DwainsWorld

Copy link
Copy Markdown

No problem. Thanks for the update and the composer patch package link - very useful!

@DwainsWorld

Copy link
Copy Markdown

@duncanmcclean

I was giving this a try with composer patch, all went well. Except, within routes/cp.php:

Shouldn't this:

if (config('statamic.cp.auth', true)) {

Be:

if (config('statamic.cp.auth.enabled', true)) {

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

@DwainsWorld Yes, it should be, thanks! I've updated this PR.

@edalzell

Copy link
Copy Markdown
Contributor

This works great for me, thanks Duncan!

Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

DwainsWorld commented May 9, 2024

Copy link
Copy Markdown

Is anyone being hit with a 404 with this PR when attempting to "Resume your session"? Is it possible to disable the ability to resume and auto logout instead?

image
image

@edalzell

Copy link
Copy Markdown
Contributor

Yes, I've run into this. This flow needs to be reconsidered when CP login is disabled. We use it in a passwordless login situation so this part makes no sense, it should log out and redirect to the appropriate page.

@duncanmccleanduncanmcclean changed the title [4.x] Ability to disable CP authentication[5.x] Ability to disable CP authenticationMay 13, 2024
@duncanmcclean
duncanmcclean changed the base branch from 4.x to 5.xMay 13, 2024 10:30
duncanmccleanand others added 6 commits May 13, 2024 12:24
# Conflicts:
#	tests/Tags/User/ForgotPasswordFormTest.php
#	tests/Tags/User/LoginFormTest.php
#	tests/Tags/User/PasswordFormTest.php
#	tests/Tags/User/RegisterFormTest.php
Instead, redirect when there's an actual 401.
Apparently it's not completely accurate. You could get a few requests that return zero. It's fine for controlling when the modal pops up, but not a redirect. If you redirect, when you hit the login page your session will be extended, keeping you logged in.
@jasonvarga
jasonvarga merged commit 7ace3c1 into 5.xJun 27, 2024
@jasonvarga
jasonvarga deleted the pr/7617 branch June 27, 2024 20:01
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
* Allow configuring the Stache's Cache Store
Related: statamic/cms#10303
* Ability to disable CP authentication
Related: statamic/cms#8960
* Display custom logo as plain text
Related: statamic/cms#10350
* Track sites.yaml path in git integration config
Related: statamic/cms#10463
* Add ability to specify the queue connection on static:warm command
Related: statamic/cms#8634
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@duncanmcclean@DwainsWorld@edalzell@ryanmitchell@jasonvarga
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[5.x] Ability to disable CP authentication - #8960

Merged
jasonvarga merged 25 commits into
5.xfrom
pr/7617
Jun 27, 2024
Merged

[5.x] Ability to disable CP authentication#8960
jasonvarga merged 25 commits into
5.xfrom
pr/7617

Conversation

@duncanmcclean

@duncanmccleanduncanmcclean commented Nov 9, 2023

Copy link
Copy Markdown
Member

This pull request implements a new config option, allowing developers to disable the Control Panel authentication pages.

Often times, if you're using something like Jetstream or Laravel Nova which provide their own login pages then you don't want an additional login page for users to somehow find their way to.

Authentication can be disabled by toggling the statamic.cp.auth.enabled option. You may optionally specify a URL for users to be redirected to instead:

<?php/*|--------------------------------------------------------------------------| Authentication|--------------------------------------------------------------------------|| Whether the Control Panel's authentication pages should be enabled,| or if users should be redirected elsewhere.|*/'auth' => [
'enabled' => false,
'redirect_to' => '/nova',
],

This PR replaces my previous PR, #7617.

@duncanmcclean
duncanmcclean marked this pull request as draft November 9, 2023 11:37
@duncanmcclean
duncanmcclean marked this pull request as ready for review November 9, 2023 12:07
Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

Copy link
Copy Markdown

Is this planned for 4.X? We would use this in almost all our apps that have a Statamic installation.

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

Sorry, we don't have an ETA for reviewing/merging this pull request. We'll get to it when we can.

In the meantime, you can pull this PR into your project with a composer patch.

@DwainsWorld

Copy link
Copy Markdown

No problem. Thanks for the update and the composer patch package link - very useful!

@DwainsWorld

Copy link
Copy Markdown

@duncanmcclean

I was giving this a try with composer patch, all went well. Except, within routes/cp.php:

Shouldn't this:

if (config('statamic.cp.auth', true)) {

Be:

if (config('statamic.cp.auth.enabled', true)) {

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

@DwainsWorld Yes, it should be, thanks! I've updated this PR.

@edalzell

Copy link
Copy Markdown
Contributor

This works great for me, thanks Duncan!

Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

DwainsWorld commented May 9, 2024

Copy link
Copy Markdown

Is anyone being hit with a 404 with this PR when attempting to "Resume your session"? Is it possible to disable the ability to resume and auto logout instead?

image
image

@edalzell

Copy link
Copy Markdown
Contributor

Yes, I've run into this. This flow needs to be reconsidered when CP login is disabled. We use it in a passwordless login situation so this part makes no sense, it should log out and redirect to the appropriate page.

@duncanmccleanduncanmcclean changed the title [4.x] Ability to disable CP authentication[5.x] Ability to disable CP authenticationMay 13, 2024
@duncanmcclean
duncanmcclean changed the base branch from 4.x to 5.xMay 13, 2024 10:30
duncanmccleanand others added 6 commits May 13, 2024 12:24
# Conflicts:
#	tests/Tags/User/ForgotPasswordFormTest.php
#	tests/Tags/User/LoginFormTest.php
#	tests/Tags/User/PasswordFormTest.php
#	tests/Tags/User/RegisterFormTest.php
Instead, redirect when there's an actual 401.
Apparently it's not completely accurate. You could get a few requests that return zero. It's fine for controlling when the modal pops up, but not a redirect. If you redirect, when you hit the login page your session will be extended, keeping you logged in.
@jasonvarga
jasonvarga merged commit 7ace3c1 into 5.xJun 27, 2024
@jasonvarga
jasonvarga deleted the pr/7617 branch June 27, 2024 20:01
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
* Allow configuring the Stache's Cache Store
Related: statamic/cms#10303
* Ability to disable CP authentication
Related: statamic/cms#8960
* Display custom logo as plain text
Related: statamic/cms#10350
* Track sites.yaml path in git integration config
Related: statamic/cms#10463
* Add ability to specify the queue connection on static:warm command
Related: statamic/cms#8634
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@duncanmcclean@DwainsWorld@edalzell@ryanmitchell@jasonvarga
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[5.x] Ability to disable CP authentication - #8960

Merged
jasonvarga merged 25 commits into
5.xfrom
pr/7617
Jun 27, 2024
Merged

[5.x] Ability to disable CP authentication#8960
jasonvarga merged 25 commits into
5.xfrom
pr/7617

Conversation

@duncanmcclean

@duncanmccleanduncanmcclean commented Nov 9, 2023

Copy link
Copy Markdown
Member

This pull request implements a new config option, allowing developers to disable the Control Panel authentication pages.

Often times, if you're using something like Jetstream or Laravel Nova which provide their own login pages then you don't want an additional login page for users to somehow find their way to.

Authentication can be disabled by toggling the statamic.cp.auth.enabled option. You may optionally specify a URL for users to be redirected to instead:

<?php/*|--------------------------------------------------------------------------| Authentication|--------------------------------------------------------------------------|| Whether the Control Panel's authentication pages should be enabled,| or if users should be redirected elsewhere.|*/'auth' => [
'enabled' => false,
'redirect_to' => '/nova',
],

This PR replaces my previous PR, #7617.

@duncanmcclean
duncanmcclean marked this pull request as draft November 9, 2023 11:37
@duncanmcclean
duncanmcclean marked this pull request as ready for review November 9, 2023 12:07
Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

Copy link
Copy Markdown

Is this planned for 4.X? We would use this in almost all our apps that have a Statamic installation.

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

Sorry, we don't have an ETA for reviewing/merging this pull request. We'll get to it when we can.

In the meantime, you can pull this PR into your project with a composer patch.

@DwainsWorld

Copy link
Copy Markdown

No problem. Thanks for the update and the composer patch package link - very useful!

@DwainsWorld

Copy link
Copy Markdown

@duncanmcclean

I was giving this a try with composer patch, all went well. Except, within routes/cp.php:

Shouldn't this:

if (config('statamic.cp.auth', true)) {

Be:

if (config('statamic.cp.auth.enabled', true)) {

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

@DwainsWorld Yes, it should be, thanks! I've updated this PR.

@edalzell

Copy link
Copy Markdown
Contributor

This works great for me, thanks Duncan!

Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

DwainsWorld commented May 9, 2024

Copy link
Copy Markdown

Is anyone being hit with a 404 with this PR when attempting to "Resume your session"? Is it possible to disable the ability to resume and auto logout instead?

image
image

@edalzell

Copy link
Copy Markdown
Contributor

Yes, I've run into this. This flow needs to be reconsidered when CP login is disabled. We use it in a passwordless login situation so this part makes no sense, it should log out and redirect to the appropriate page.

@duncanmccleanduncanmcclean changed the title [4.x] Ability to disable CP authentication[5.x] Ability to disable CP authenticationMay 13, 2024
@duncanmcclean
duncanmcclean changed the base branch from 4.x to 5.xMay 13, 2024 10:30
duncanmccleanand others added 6 commits May 13, 2024 12:24
# Conflicts:
#	tests/Tags/User/ForgotPasswordFormTest.php
#	tests/Tags/User/LoginFormTest.php
#	tests/Tags/User/PasswordFormTest.php
#	tests/Tags/User/RegisterFormTest.php
Instead, redirect when there's an actual 401.
Apparently it's not completely accurate. You could get a few requests that return zero. It's fine for controlling when the modal pops up, but not a redirect. If you redirect, when you hit the login page your session will be extended, keeping you logged in.
@jasonvarga
jasonvarga merged commit 7ace3c1 into 5.xJun 27, 2024
@jasonvarga
jasonvarga deleted the pr/7617 branch June 27, 2024 20:01
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
* Allow configuring the Stache's Cache Store
Related: statamic/cms#10303
* Ability to disable CP authentication
Related: statamic/cms#8960
* Display custom logo as plain text
Related: statamic/cms#10350
* Track sites.yaml path in git integration config
Related: statamic/cms#10463
* Add ability to specify the queue connection on static:warm command
Related: statamic/cms#8634
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@duncanmcclean@DwainsWorld@edalzell@ryanmitchell@jasonvarga
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[5.x] Ability to disable CP authentication - #8960

Merged
jasonvarga merged 25 commits into
5.xfrom
pr/7617
Jun 27, 2024
Merged

[5.x] Ability to disable CP authentication#8960
jasonvarga merged 25 commits into
5.xfrom
pr/7617

Conversation

@duncanmcclean

@duncanmccleanduncanmcclean commented Nov 9, 2023

Copy link
Copy Markdown
Member

This pull request implements a new config option, allowing developers to disable the Control Panel authentication pages.

Often times, if you're using something like Jetstream or Laravel Nova which provide their own login pages then you don't want an additional login page for users to somehow find their way to.

Authentication can be disabled by toggling the statamic.cp.auth.enabled option. You may optionally specify a URL for users to be redirected to instead:

<?php/*|--------------------------------------------------------------------------| Authentication|--------------------------------------------------------------------------|| Whether the Control Panel's authentication pages should be enabled,| or if users should be redirected elsewhere.|*/'auth' => [
'enabled' => false,
'redirect_to' => '/nova',
],

This PR replaces my previous PR, #7617.

@duncanmcclean
duncanmcclean marked this pull request as draft November 9, 2023 11:37
@duncanmcclean
duncanmcclean marked this pull request as ready for review November 9, 2023 12:07
Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

Copy link
Copy Markdown

Is this planned for 4.X? We would use this in almost all our apps that have a Statamic installation.

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

Sorry, we don't have an ETA for reviewing/merging this pull request. We'll get to it when we can.

In the meantime, you can pull this PR into your project with a composer patch.

@DwainsWorld

Copy link
Copy Markdown

No problem. Thanks for the update and the composer patch package link - very useful!

@DwainsWorld

Copy link
Copy Markdown

@duncanmcclean

I was giving this a try with composer patch, all went well. Except, within routes/cp.php:

Shouldn't this:

if (config('statamic.cp.auth', true)) {

Be:

if (config('statamic.cp.auth.enabled', true)) {

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

@DwainsWorld Yes, it should be, thanks! I've updated this PR.

@edalzell

Copy link
Copy Markdown
Contributor

This works great for me, thanks Duncan!

Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

DwainsWorld commented May 9, 2024

Copy link
Copy Markdown

Is anyone being hit with a 404 with this PR when attempting to "Resume your session"? Is it possible to disable the ability to resume and auto logout instead?

image
image

@edalzell

Copy link
Copy Markdown
Contributor

Yes, I've run into this. This flow needs to be reconsidered when CP login is disabled. We use it in a passwordless login situation so this part makes no sense, it should log out and redirect to the appropriate page.

@duncanmccleanduncanmcclean changed the title [4.x] Ability to disable CP authentication[5.x] Ability to disable CP authenticationMay 13, 2024
@duncanmcclean
duncanmcclean changed the base branch from 4.x to 5.xMay 13, 2024 10:30
duncanmccleanand others added 6 commits May 13, 2024 12:24
# Conflicts:
#	tests/Tags/User/ForgotPasswordFormTest.php
#	tests/Tags/User/LoginFormTest.php
#	tests/Tags/User/PasswordFormTest.php
#	tests/Tags/User/RegisterFormTest.php
Instead, redirect when there's an actual 401.
Apparently it's not completely accurate. You could get a few requests that return zero. It's fine for controlling when the modal pops up, but not a redirect. If you redirect, when you hit the login page your session will be extended, keeping you logged in.
@jasonvarga
jasonvarga merged commit 7ace3c1 into 5.xJun 27, 2024
@jasonvarga
jasonvarga deleted the pr/7617 branch June 27, 2024 20:01
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
* Allow configuring the Stache's Cache Store
Related: statamic/cms#10303
* Ability to disable CP authentication
Related: statamic/cms#8960
* Display custom logo as plain text
Related: statamic/cms#10350
* Track sites.yaml path in git integration config
Related: statamic/cms#10463
* Add ability to specify the queue connection on static:warm command
Related: statamic/cms#8634
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@duncanmcclean@DwainsWorld@edalzell@ryanmitchell@jasonvarga
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[5.x] Ability to disable CP authentication - #8960

Merged
jasonvarga merged 25 commits into
5.xfrom
pr/7617
Jun 27, 2024
Merged

[5.x] Ability to disable CP authentication#8960
jasonvarga merged 25 commits into
5.xfrom
pr/7617

Conversation

@duncanmcclean

@duncanmccleanduncanmcclean commented Nov 9, 2023

Copy link
Copy Markdown
Member

This pull request implements a new config option, allowing developers to disable the Control Panel authentication pages.

Often times, if you're using something like Jetstream or Laravel Nova which provide their own login pages then you don't want an additional login page for users to somehow find their way to.

Authentication can be disabled by toggling the statamic.cp.auth.enabled option. You may optionally specify a URL for users to be redirected to instead:

<?php/*|--------------------------------------------------------------------------| Authentication|--------------------------------------------------------------------------|| Whether the Control Panel's authentication pages should be enabled,| or if users should be redirected elsewhere.|*/'auth' => [
'enabled' => false,
'redirect_to' => '/nova',
],

This PR replaces my previous PR, #7617.

@duncanmcclean
duncanmcclean marked this pull request as draft November 9, 2023 11:37
@duncanmcclean
duncanmcclean marked this pull request as ready for review November 9, 2023 12:07
Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

Copy link
Copy Markdown

Is this planned for 4.X? We would use this in almost all our apps that have a Statamic installation.

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

Sorry, we don't have an ETA for reviewing/merging this pull request. We'll get to it when we can.

In the meantime, you can pull this PR into your project with a composer patch.

@DwainsWorld

Copy link
Copy Markdown

No problem. Thanks for the update and the composer patch package link - very useful!

@DwainsWorld

Copy link
Copy Markdown

@duncanmcclean

I was giving this a try with composer patch, all went well. Except, within routes/cp.php:

Shouldn't this:

if (config('statamic.cp.auth', true)) {

Be:

if (config('statamic.cp.auth.enabled', true)) {

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

@DwainsWorld Yes, it should be, thanks! I've updated this PR.

@edalzell

Copy link
Copy Markdown
Contributor

This works great for me, thanks Duncan!

Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

DwainsWorld commented May 9, 2024

Copy link
Copy Markdown

Is anyone being hit with a 404 with this PR when attempting to "Resume your session"? Is it possible to disable the ability to resume and auto logout instead?

image
image

@edalzell

Copy link
Copy Markdown
Contributor

Yes, I've run into this. This flow needs to be reconsidered when CP login is disabled. We use it in a passwordless login situation so this part makes no sense, it should log out and redirect to the appropriate page.

@duncanmccleanduncanmcclean changed the title [4.x] Ability to disable CP authentication[5.x] Ability to disable CP authenticationMay 13, 2024
@duncanmcclean
duncanmcclean changed the base branch from 4.x to 5.xMay 13, 2024 10:30
duncanmccleanand others added 6 commits May 13, 2024 12:24
# Conflicts:
#	tests/Tags/User/ForgotPasswordFormTest.php
#	tests/Tags/User/LoginFormTest.php
#	tests/Tags/User/PasswordFormTest.php
#	tests/Tags/User/RegisterFormTest.php
Instead, redirect when there's an actual 401.
Apparently it's not completely accurate. You could get a few requests that return zero. It's fine for controlling when the modal pops up, but not a redirect. If you redirect, when you hit the login page your session will be extended, keeping you logged in.
@jasonvarga
jasonvarga merged commit 7ace3c1 into 5.xJun 27, 2024
@jasonvarga
jasonvarga deleted the pr/7617 branch June 27, 2024 20:01
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
* Allow configuring the Stache's Cache Store
Related: statamic/cms#10303
* Ability to disable CP authentication
Related: statamic/cms#8960
* Display custom logo as plain text
Related: statamic/cms#10350
* Track sites.yaml path in git integration config
Related: statamic/cms#10463
* Add ability to specify the queue connection on static:warm command
Related: statamic/cms#8634
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@duncanmcclean@DwainsWorld@edalzell@ryanmitchell@jasonvarga
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[5.x] Ability to disable CP authentication - #8960

Merged
jasonvarga merged 25 commits into
5.xfrom
pr/7617
Jun 27, 2024
Merged

[5.x] Ability to disable CP authentication#8960
jasonvarga merged 25 commits into
5.xfrom
pr/7617

Conversation

@duncanmcclean

@duncanmccleanduncanmcclean commented Nov 9, 2023

Copy link
Copy Markdown
Member

This pull request implements a new config option, allowing developers to disable the Control Panel authentication pages.

Often times, if you're using something like Jetstream or Laravel Nova which provide their own login pages then you don't want an additional login page for users to somehow find their way to.

Authentication can be disabled by toggling the statamic.cp.auth.enabled option. You may optionally specify a URL for users to be redirected to instead:

<?php/*|--------------------------------------------------------------------------| Authentication|--------------------------------------------------------------------------|| Whether the Control Panel's authentication pages should be enabled,| or if users should be redirected elsewhere.|*/'auth' => [
'enabled' => false,
'redirect_to' => '/nova',
],

This PR replaces my previous PR, #7617.

@duncanmcclean
duncanmcclean marked this pull request as draft November 9, 2023 11:37
@duncanmcclean
duncanmcclean marked this pull request as ready for review November 9, 2023 12:07
Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

Copy link
Copy Markdown

Is this planned for 4.X? We would use this in almost all our apps that have a Statamic installation.

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

Sorry, we don't have an ETA for reviewing/merging this pull request. We'll get to it when we can.

In the meantime, you can pull this PR into your project with a composer patch.

@DwainsWorld

Copy link
Copy Markdown

No problem. Thanks for the update and the composer patch package link - very useful!

@DwainsWorld

Copy link
Copy Markdown

@duncanmcclean

I was giving this a try with composer patch, all went well. Except, within routes/cp.php:

Shouldn't this:

if (config('statamic.cp.auth', true)) {

Be:

if (config('statamic.cp.auth.enabled', true)) {

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

@DwainsWorld Yes, it should be, thanks! I've updated this PR.

@edalzell

Copy link
Copy Markdown
Contributor

This works great for me, thanks Duncan!

Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

DwainsWorld commented May 9, 2024

Copy link
Copy Markdown

Is anyone being hit with a 404 with this PR when attempting to "Resume your session"? Is it possible to disable the ability to resume and auto logout instead?

image
image

@edalzell

Copy link
Copy Markdown
Contributor

Yes, I've run into this. This flow needs to be reconsidered when CP login is disabled. We use it in a passwordless login situation so this part makes no sense, it should log out and redirect to the appropriate page.

@duncanmccleanduncanmcclean changed the title [4.x] Ability to disable CP authentication[5.x] Ability to disable CP authenticationMay 13, 2024
@duncanmcclean
duncanmcclean changed the base branch from 4.x to 5.xMay 13, 2024 10:30
duncanmccleanand others added 6 commits May 13, 2024 12:24
# Conflicts:
#	tests/Tags/User/ForgotPasswordFormTest.php
#	tests/Tags/User/LoginFormTest.php
#	tests/Tags/User/PasswordFormTest.php
#	tests/Tags/User/RegisterFormTest.php
Instead, redirect when there's an actual 401.
Apparently it's not completely accurate. You could get a few requests that return zero. It's fine for controlling when the modal pops up, but not a redirect. If you redirect, when you hit the login page your session will be extended, keeping you logged in.
@jasonvarga
jasonvarga merged commit 7ace3c1 into 5.xJun 27, 2024
@jasonvarga
jasonvarga deleted the pr/7617 branch June 27, 2024 20:01
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
* Allow configuring the Stache's Cache Store
Related: statamic/cms#10303
* Ability to disable CP authentication
Related: statamic/cms#8960
* Display custom logo as plain text
Related: statamic/cms#10350
* Track sites.yaml path in git integration config
Related: statamic/cms#10463
* Add ability to specify the queue connection on static:warm command
Related: statamic/cms#8634
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@duncanmcclean@DwainsWorld@edalzell@ryanmitchell@jasonvarga
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[5.x] Ability to disable CP authentication - #8960

Merged
jasonvarga merged 25 commits into
5.xfrom
pr/7617
Jun 27, 2024
Merged

[5.x] Ability to disable CP authentication#8960
jasonvarga merged 25 commits into
5.xfrom
pr/7617

Conversation

@duncanmcclean

@duncanmccleanduncanmcclean commented Nov 9, 2023

Copy link
Copy Markdown
Member

This pull request implements a new config option, allowing developers to disable the Control Panel authentication pages.

Often times, if you're using something like Jetstream or Laravel Nova which provide their own login pages then you don't want an additional login page for users to somehow find their way to.

Authentication can be disabled by toggling the statamic.cp.auth.enabled option. You may optionally specify a URL for users to be redirected to instead:

<?php/*|--------------------------------------------------------------------------| Authentication|--------------------------------------------------------------------------|| Whether the Control Panel's authentication pages should be enabled,| or if users should be redirected elsewhere.|*/'auth' => [
'enabled' => false,
'redirect_to' => '/nova',
],

This PR replaces my previous PR, #7617.

@duncanmcclean
duncanmcclean marked this pull request as draft November 9, 2023 11:37
@duncanmcclean
duncanmcclean marked this pull request as ready for review November 9, 2023 12:07
Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

Copy link
Copy Markdown

Is this planned for 4.X? We would use this in almost all our apps that have a Statamic installation.

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

Sorry, we don't have an ETA for reviewing/merging this pull request. We'll get to it when we can.

In the meantime, you can pull this PR into your project with a composer patch.

@DwainsWorld

Copy link
Copy Markdown

No problem. Thanks for the update and the composer patch package link - very useful!

@DwainsWorld

Copy link
Copy Markdown

@duncanmcclean

I was giving this a try with composer patch, all went well. Except, within routes/cp.php:

Shouldn't this:

if (config('statamic.cp.auth', true)) {

Be:

if (config('statamic.cp.auth.enabled', true)) {

@duncanmcclean

Copy link
Copy Markdown
MemberAuthor

@DwainsWorld Yes, it should be, thanks! I've updated this PR.

@edalzell

Copy link
Copy Markdown
Contributor

This works great for me, thanks Duncan!

Comment threadsrc/Exceptions/AuthenticationException.php Outdated
@DwainsWorld

DwainsWorld commented May 9, 2024

Copy link
Copy Markdown

Is anyone being hit with a 404 with this PR when attempting to "Resume your session"? Is it possible to disable the ability to resume and auto logout instead?

image
image

@edalzell

Copy link
Copy Markdown
Contributor

Yes, I've run into this. This flow needs to be reconsidered when CP login is disabled. We use it in a passwordless login situation so this part makes no sense, it should log out and redirect to the appropriate page.

@duncanmccleanduncanmcclean changed the title [4.x] Ability to disable CP authentication[5.x] Ability to disable CP authenticationMay 13, 2024
@duncanmcclean
duncanmcclean changed the base branch from 4.x to 5.xMay 13, 2024 10:30
duncanmccleanand others added 6 commits May 13, 2024 12:24
# Conflicts:
#	tests/Tags/User/ForgotPasswordFormTest.php
#	tests/Tags/User/LoginFormTest.php
#	tests/Tags/User/PasswordFormTest.php
#	tests/Tags/User/RegisterFormTest.php
Instead, redirect when there's an actual 401.
Apparently it's not completely accurate. You could get a few requests that return zero. It's fine for controlling when the modal pops up, but not a redirect. If you redirect, when you hit the login page your session will be extended, keeping you logged in.
@jasonvarga
jasonvarga merged commit 7ace3c1 into 5.xJun 27, 2024
@jasonvarga
jasonvarga deleted the pr/7617 branch June 27, 2024 20:01
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
duncanmcclean added a commit to statamic/statamic that referenced this pull request Aug 7, 2024
* Allow configuring the Stache's Cache Store
Related: statamic/cms#10303
* Ability to disable CP authentication
Related: statamic/cms#8960
* Display custom logo as plain text
Related: statamic/cms#10350
* Track sites.yaml path in git integration config
Related: statamic/cms#10463
* Add ability to specify the queue connection on static:warm command
Related: statamic/cms#8634
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@duncanmcclean@DwainsWorld@edalzell@ryanmitchell@jasonvarga