Deploy Ladill Queue / deploy (push) Successful in 55s
Replace local member UUID invites with platform email invites, SSO post-auth redirect, and provisioner-backed pending access until accept. Co-authored-by: Cursor <cursoragent@cursor.com>
75 lines
2.1 KiB
PHP
75 lines
2.1 KiB
PHP
<?php
|
|
|
|
namespace App\Services\Identity;
|
|
|
|
use Illuminate\Http\Client\Response;
|
|
use Illuminate\Support\Facades\Http;
|
|
use RuntimeException;
|
|
|
|
class IdentityTeamClient
|
|
{
|
|
/**
|
|
* @param list<string> $apps
|
|
* @param array<string, mixed> $metadata
|
|
*
|
|
* @return array<string, mixed>
|
|
*/
|
|
public function inviteAppMember(
|
|
string $ownerPublicId,
|
|
string $email,
|
|
array $apps,
|
|
array $metadata = [],
|
|
string $role = 'member',
|
|
): array {
|
|
$response = $this->request('post', '/identity/team/invite', [
|
|
'owner' => $ownerPublicId,
|
|
'email' => strtolower(trim($email)),
|
|
'apps' => $apps,
|
|
'role' => $role,
|
|
'metadata' => $metadata,
|
|
]);
|
|
|
|
return (array) $response->json('data', []);
|
|
}
|
|
|
|
public function postAuthRedirect(string $userPublicId, string $intendedUrl): string
|
|
{
|
|
$response = $this->request('get', '/identity/team/post-auth-redirect', [
|
|
'user' => $userPublicId,
|
|
'redirect' => $intendedUrl,
|
|
]);
|
|
|
|
return (string) $response->json('data.url', $intendedUrl);
|
|
}
|
|
|
|
/** @return list<array<string, mixed>> */
|
|
public function teamAccess(string $userPublicId): array
|
|
{
|
|
$response = $this->request('get', '/identity/team/access', [
|
|
'user' => $userPublicId,
|
|
]);
|
|
|
|
return (array) $response->json('data', []);
|
|
}
|
|
|
|
private function request(string $method, string $path, array $query = []): Response
|
|
{
|
|
$url = rtrim((string) config('identity.api_url'), '/').$path;
|
|
$key = config('identity.api_key');
|
|
|
|
if ($url === '' || ! is_string($key) || $key === '') {
|
|
throw new RuntimeException('Identity API is not configured.');
|
|
}
|
|
|
|
$response = Http::withToken($key)
|
|
->timeout(10)
|
|
->{$method}($url, $query);
|
|
|
|
if (! $response->successful()) {
|
|
throw new RuntimeException($response->json('message') ?: 'Identity API request failed.');
|
|
}
|
|
|
|
return $response;
|
|
}
|
|
}
|