If i login to my external app via passport as shown in many tutorial:
public function login(Request $request)
{
$data=$request->all();
$validator = Validator::make($data, [
'email' => 'email|required',
'password' => 'required'
]);
if($validator->fails()){
return response()->json(['error' => $validator->errors(), 'Validation Error',400]);
}
if (!auth()->attempt($data)) {
return response(['message' => 'Invalid Credentials'],400);
}
$accessToken = auth()->user()->createToken('authToken')->accessToken;
return response()->json(['user' => auth()->user(), 'access_token' => $accessToken], 200);
}
I've read lots of post, howto and seen some video, but there is not a clear procedure to logout an user in this scenario, and laravel's manual do not said anything about it ( why? or where is it).
I found as possible solutions:
auth()->user()->token()->revoke();$request->user()->token()->revoke();auth()->logout();$request->session()->invalidate();
Which of these performs the rights step for logout? My method should looks something like:
public function logout(Request $request) {
//auth()->user()->token()->revoke();
//$request->user()->token()->revoke();
// auth()->logout();
//$request->session()->invalidate();
return response()->json(['message' => 'User successfully signed out'], 200);
}
and the routhe should be:
Route::post('/logout', [AuthController::class, 'logout'])->middleware('auth:api');
or I wrong???
Even how to not redirect to login route if an user is not authenticated to see a resource? If im send back:
class Authenticate extends Middleware
{
/**
* Get the path the user should be redirected to when they are not authenticated.
*
* @param \Illuminate\Http\Request $request
* @return string|null
*/
protected function redirectTo($request)
{
if (! $request->expectsJson()) {
response()->json(['mex'=>'not authorized'], 401);
}
}
}
not works and send me back an error:
ErrorException: Header may not contain more than a single header, new line detected in file ...../vendor/symfony/http-foundation/Response.php on line 359