Skip to content

feat(identity): restrict password login to local env - #567

Open
gvieira18 wants to merge 10 commits into
4.xfrom
story/521-credential-login-gate
Open

gvieira18 wants to merge 10 commits into
4.xfrom
story/521-credential-login-gate

Conversation

@gvieira18

@gvieira18 gvieira18 commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Contexto

A tela de login oferece e-mail e senha, mas não tem fluxo de criação ou recuperação de conta. Quem esquece a senha fica sem acesso. Na discussão da issue, a decisão foi remover o login por credenciais fora do ambiente local: o público da He4rt já tem conta no Discord ou no GitHub.

Com esta mudança, staging e produção mostram só o login social. Em local, o formulário continua disponível e vem preenchido com o usuário de desenvolvimento.

Alterações

  • he4rt: componentes compartilhados <x-he4rt::auth.social-login /> e <x-he4rt::auth.credential-login>. Os botões sociais vêm de IdentityProvider, só com os providers OAuth2 habilitados. As traduções ficam em he4rt::auth (en e pt_BR).
  • identity: a trait DisablesCredentialLoginOutsideLocal esvazia o formulário e responde 404 no authenticate() fora de local.
  • panel-app: o login usa os componentes e a trait. O preenchimento automático agora vale só em local (antes valia também em staging).
  • panel-admin: a página App\Filament\Pages\Login foi movida para He4rt\PanelAdmin\Pages\Login, com view própria e login social.
  • Atualização de dependências do Composer e do npm, pest shards regenerados e um ajuste do Rector em ShortLinkResourceTest.

Plano de Testes

  • Rector, Pint e PHPStan sem erros
  • Suíte completa: php artisan test --compact --parallel (1743 testes passando)
  • Novos testes: CredentialLoginGateTest (app) e AdminLoginCredentialGateTest (admin) cobrem formulário oculto fora de local, formulário visível em local e authenticate() com 404 fora de local
  • Abrir /app/login e /admin/login em staging e confirmar que só aparecem os botões sociais

Evidências

Antes: login com e-mail e senha, sem recuperação de conta Tela de login antes Erro de login sem opção de recuperação
Depois: /app/login fora de local (só login social) image
Depois: /admin/login fora de local (só login social) image
Depois: login em ambiente local (social + e-mail e senha) image image

Issues Relacionadas

Closes #521

@gvieira18
gvieira18 requested a review from a team September 26, 2026 03:21
@gvieira18 gvieira18 self-assigned this Sep 26, 2026
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Advanced

Run ID: af505283-8798-4a5d-9c09-e8f0bffdb07f

📥 Commits

Reviewing files that changed from the base of the PR and between 3c58711 and 3dfd006.

⛔ Files ignored due to path filters (2)
  • composer.lock is excluded by !**/*.lock
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (3)
  • composer.json
  • package.json
  • tests/.pest/shards.json
🚧 Files skipped from review as they are similar to previous changes (1)
  • tests/.pest/shards.json

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

Shared localized authentication components are added, and app and admin login pages use them. Credential fields and authentication are restricted to local environments, and default credentials are filled only locally. Dependency constraints and test shard timings are updated.

Suggested reviewers: 1pride

Priority: ➖ Normal

Change: Feature

Merge Risk: ⚪ Minimal · up to 3dfd0

No material issue was found in the reviewed login changes or dependency updates. The PR appears ready to merge after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 3dfd0

The change narrows password-login exposure and enforces the restriction on the server, not just in the interface. No introduced authorization bypass was established. Remaining uncertainty concerns admin authorization after social login and whether deployed providers and privileged accounts are ready for social-only access.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — The changed authentication surface covers the app and admin panels. Panel-selectable OAuth initiation and browser callback login already exist in the available target-branch merge base; adding admin social buttons therefore does not, by itself, establish a newly reachable privileged authentication path.

Trust Boundaries and Controls

  • observed — The credential restriction is enforced before parent authentication and is not merely a hidden form. Browser-controlled lastAuthProvider data only selects a display badge from the rendered provider list; it does not select an authenticated identity or grant panel authority.
  • observed — OAuth state is encrypted and carries intent, provider, panel, and return URL. Link processing requires a current authenticated User rather than accepting an owner identifier from the callback. These controls do not establish state expiry, session binding, or replay protection.

Resilience and Maintainability Implications

  • observed — Provider persistence searches within the owner's connections before saving credentials and emitting a connection event. User creation and provider persistence are separate steps in the inspected flow; the evidence does not prove transaction-wide rollback, exactly-once event handling, or concurrency-safe recovery.

Hardening Proposals

  • proposed — Before rollout, verify enabled OAuth providers and privileged-account access, exercise non-super-admin denial through the actual admin callback and subsequent protected request, and establish a recovery path that does not require enabling local-environment behavior in a deployed environment.
🚥 Pre-merge checks | ✅ 2 | ❌ 3

❌ Failed checks (3 warnings)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning Issue #521 requires a password-recovery link or button for credential users. The PR adds no recovery control or recovery flow. It instead hides credential login and aborts authentication outside local… Add and test the password-recovery link or button required by #521, or update the linked issue to document an intentional requirement change.
Out of Scope Changes check ⚠️ Warning The PR changes authentication policy, adds shared social-login components, relocates the admin login page, updates dependencies, and regenerates Pest shard data. These changes do not implement passwor… Limit this PR to password recovery and supporting tests, or link issues that justify the authentication-policy, admin-login, dependency, and shard changes.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 14 files. (3 skipped: 3… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: restricting password login to the local environment.
Description check ✅ Passed The description includes the required context, changes, test plan, evidence, and related issue. It provides specific validation results and affected components.
Full details: Linked Issues check

Explanation

Issue #521 requires a password-recovery link or button for credential users. The PR adds no recovery control or recovery flow. It instead hides credential login and aborts authentication outside local environments. The added tests cover the environment gate, not password recovery.

Full details: Out of Scope Changes check

Explanation

The PR changes authentication policy, adds shared social-login components, relocates the admin login page, updates dependencies, and regenerates Pest shard data. These changes do not implement password recovery for #521. The dependency and shard changes have no demonstrated connection to that objective.

Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 14 files. (3 skipped: 3 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

danielhe4rt
danielhe4rt previously approved these changes Sep 28, 2026
DiogoKaster
DiogoKaster previously approved these changes Sep 28, 2026
Clintonrocha98
Clintonrocha98 previously approved these changes Sep 28, 2026
thalesmengue
thalesmengue previously approved these changes Sep 28, 2026

@evelynlacerda evelynlacerda left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

hefeus
hefeus previously approved these changes Sep 28, 2026

@hefeus hefeus left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@buzinei-bibi buzinei-bibi left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

…ogin-gate

# Conflicts:
#	composer.json
#	composer.lock
#	package-lock.json
#	package.json

@hefeus hefeus left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: Tela de login não permite criar ou recuperar conta, exceto social logins