Conversation
There was a problem hiding this comment.
Pull request overview
This PR adds an api-logs.guard configuration option to control which Laravel auth guard is used by the LogApiRequest middleware when resolving the authenticated user (“causer”) for an API log entry, addressing cases where the default guard may not reflect the API’s authentication guard.
Changes:
- Added
guardoption (defaultnull) toconfig/api-logs.phpto optionally pin the guard used for user resolution. - Updated
LogApiRequestmiddleware to resolve the user via the configured guard. - Added feature tests and README documentation covering configured-guard behavior.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
src/Http/Middleware/LogApiRequest.php |
Uses config('api-logs.guard') to select the auth guard for resolving the user before logging. |
config/api-logs.php |
Introduces documented guard config option with default null to preserve current behavior. |
tests/Feature/LogApiRequestMiddlewareTest.php |
Adds tests verifying the configured guard is used and that logs are skipped when that guard is unauthenticated. |
README.md |
Documents the new guard config option and updates the config publishing section accordingly. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #30
The
LogApiRequestmiddleware resolved the user viaauth()->user(), i.e. the request's default guard. When noauth:<guard>middleware had calledshouldUse(), this silently fell back toconfig('auth.defaults.guard')(typicallyweb), which may not be the guard the application authenticates its API with.This PR adds a
guardoption toconfig/api-logs.php:'guard' => null(default) keeps the current behavior — the request's default guard is used.'sanctum') pins the guard used to resolve the user a logged request is attributed to.Includes feature tests covering both the configured-guard-authenticated and configured-guard-unauthenticated cases, plus README documentation.