Add Phase 1 Identity & Access module (roles, tokens, panel auth, policies)

Implements T1.1-T1.4: Spatie role/permission seeding, Sanctum token
issuance for customer channels and the FastAPI agent (with an
ability-exact-match middleware to tell them apart), Filament admin
panel access restricted to admin-tier roles with the navigation group
order, and skeleton BookingPolicy/RoutePolicy gated on the seeded
permissions ahead of their models landing in later phases.
This commit is contained in:
Nyan Lin Paing
2026-08-05 00:27:41 +07:00
parent cfa5aed15c
commit 17dd5acd23
22 changed files with 569 additions and 12 deletions
@@ -0,0 +1,37 @@
<?php
namespace Modules\Identity\Http\Controllers;
use App\Models\User;
use Illuminate\Routing\Controller;
use Illuminate\Support\Facades\Hash;
use Illuminate\Validation\ValidationException;
use Modules\Identity\Enums\TokenAbility;
use Modules\Identity\Http\Requests\IssueTokenRequest;
class TokenController extends Controller
{
/**
* Exchange customer credentials (mini app / mobile app) for a Sanctum
* token carrying the full customer ability set.
*/
public function store(IssueTokenRequest $request): array
{
$user = User::where('email', $request->string('email'))->first();
if (! $user || ! Hash::check($request->string('password'), $user->password)) {
throw ValidationException::withMessages([
'email' => ['The provided credentials are incorrect.'],
]);
}
$token = $user->createToken(
$request->string('device_name')->toString(),
TokenAbility::customerAbilities(),
);
return [
'token' => $token->plainTextToken,
];
}
}