Add platform admin hosting API for Ladill account provisioning.
Deploy Ladill Hosting / deploy (push) Successful in 1m29s

Expose authenticated service endpoints for assigning, listing, renewing, and managing hosting accounts from the platform, with tests and deploy docs.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
isaacclad
2026-07-03 22:54:00 +00:00
co-authored by Cursor
parent b0e1cfab4e
commit 2c9877a87c
14 changed files with 806 additions and 66 deletions
@@ -0,0 +1,123 @@
<?php
namespace App\Http\Controllers\Api;
use App\Http\Controllers\Controller;
use App\Models\HostingAccount;
use App\Services\Hosting\AdminHostingAssignmentService;
use App\Services\Hosting\HostingResourcePolicyService;
use App\Services\Platform\PlatformUserResolver;
use Illuminate\Http\JsonResponse;
use Illuminate\Http\Request;
class PlatformHostingController extends Controller
{
public function products(AdminHostingAssignmentService $assignments): JsonResponse
{
return response()->json([
'data' => $assignments->listProducts(),
]);
}
public function index(string $publicId, PlatformUserResolver $users, AdminHostingAssignmentService $assignments): JsonResponse
{
$owner = $users->resolveOrCreate($publicId);
if (! $owner) {
return response()->json(['data' => []]);
}
$accounts = HostingAccount::query()
->where('user_id', $owner->id)
->with('product')
->latest()
->get()
->map(fn (HostingAccount $account) => $assignments->serializeAccount($account))
->values()
->all();
return response()->json(['data' => $accounts]);
}
public function assign(
Request $request,
string $publicId,
PlatformUserResolver $users,
AdminHostingAssignmentService $assignments,
): JsonResponse {
$validated = $request->validate([
'hosting_product_id' => ['required', 'integer', 'exists:hosting_products,id'],
'duration_months' => ['required', 'integer', 'min:1', 'max:120'],
'primary_domain' => ['nullable', 'string', 'max:255'],
'username' => ['nullable', 'string', 'max:32'],
'notes' => ['nullable', 'string', 'max:1000'],
'owner_email' => ['required', 'email', 'max:255'],
'owner_name' => ['nullable', 'string', 'max:255'],
'assigned_by_admin' => ['nullable', 'integer'],
]);
$owner = $users->resolveOrCreate(
$publicId,
(string) $validated['owner_email'],
(string) ($validated['owner_name'] ?? ''),
);
if (! $owner) {
return response()->json(['error' => 'User not found.'], 404);
}
$result = $assignments->assign($owner, $validated);
return response()->json(['data' => $result], 201);
}
public function updateDuration(
Request $request,
int $account,
AdminHostingAssignmentService $assignments,
): JsonResponse {
$validated = $request->validate([
'duration_months' => ['required', 'integer', 'min:1', 'max:120'],
'admin_id' => ['nullable', 'integer'],
]);
$hostingAccount = HostingAccount::query()->findOrFail($account);
$data = $assignments->updateDuration(
$hostingAccount,
(int) $validated['duration_months'],
isset($validated['admin_id']) ? (int) $validated['admin_id'] : null,
);
return response()->json(['data' => $data]);
}
public function renew(
Request $request,
int $account,
AdminHostingAssignmentService $assignments,
): JsonResponse {
$validated = $request->validate([
'admin_id' => ['nullable', 'integer'],
]);
$hostingAccount = HostingAccount::query()->findOrFail($account);
$data = $assignments->renew(
$hostingAccount,
isset($validated['admin_id']) ? (int) $validated['admin_id'] : null,
);
return response()->json(['data' => $data]);
}
public function unsuspend(
int $account,
AdminHostingAssignmentService $assignments,
HostingResourcePolicyService $resourcePolicy,
): JsonResponse {
$hostingAccount = HostingAccount::query()->findOrFail($account);
$assignments->unsuspend($hostingAccount, $resourcePolicy);
return response()->json(['data' => ['ok' => true]]);
}
}
@@ -0,0 +1,37 @@
<?php
namespace App\Http\Middleware;
use Closure;
use Illuminate\Http\Request;
use Symfony\Component\HttpFoundation\Response;
/**
* Generic service-to-service auth for internal APIs. Validates the bearer token
* against per-consumer keys in config("{namespace}.service_api_keys").
*/
class AuthenticateService
{
public function handle(Request $request, Closure $next, string $namespace = 'platform'): Response
{
$token = (string) $request->bearerToken();
$caller = null;
if ($token !== '') {
foreach ((array) config("{$namespace}.service_api_keys", []) as $name => $key) {
if (is_string($key) && $key !== '' && hash_equals($key, $token)) {
$caller = $name;
break;
}
}
}
if ($caller === null) {
return response()->json(['error' => 'Unauthorized.'], 401);
}
$request->attributes->set('service_caller', $caller);
return $next($request);
}
}