Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 0 additions & 4 deletions src/PossessionManager.php
Original file line number Diff line number Diff line change
Expand Up @@ -95,9 +95,5 @@ protected function logoutAndDestroySession ( $guard = null ): void
} else {
Auth::logout();
}

Session::invalidate();
Session::regenerateToken();
Session::flush();
}
}
100 changes: 100 additions & 0 deletions tests/SessionFlushTest.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,100 @@
<?php

namespace Verseles\Possession\Tests;

use Illuminate\Support\Facades\Schema;
use Illuminate\Database\Schema\Blueprint;
use Illuminate\Support\Facades\Session;
use Verseles\Possession\Facades\Possession;
use Illuminate\Foundation\Auth\User as Authenticatable;
use Verseles\Possession\Traits\ImpersonatesUsers;
use Illuminate\Support\Facades\Config;

class SessionFlushTest extends TestCase
{
protected function setUp(): void
{
parent::setUp();

// Ensure users table exists
Schema::create('users', function (Blueprint $table) {
$table->id();
$table->string('name');
$table->string('email')->unique();
$table->string('password');
$table->timestamps();
});

Config::set('auth.providers.users.model', SessionFlushAdminStub::class);
}

public function test_it_preserves_unrelated_session_state_when_impersonating()
{
$admin = SessionFlushAdminStub::create([
'name' => 'Admin',
'email' => 'admin@example.com',
'password' => bcrypt('password'),
]);

$user = SessionFlushUserStub::create([
'name' => 'User',
'email' => 'user@example.com',
'password' => bcrypt('password'),
]);

$this->actingAs($admin, config('possession.admin_guard'));

// Set an unrelated application session state
Session::put('shopping_cart', ['item_1', 'item_2']);

Possession::possess($user);

// Assert session state is preserved
$this->assertTrue(Session::has('shopping_cart'));
$this->assertEquals(['item_1', 'item_2'], Session::get('shopping_cart'));
}

public function test_it_preserves_unrelated_session_state_when_unimpersonating()
{
$admin = SessionFlushAdminStub::create([
'name' => 'Admin',
'email' => 'admin@example.com',
'password' => bcrypt('password'),
]);

$user = SessionFlushUserStub::create([
'name' => 'User',
'email' => 'user@example.com',
'password' => bcrypt('password'),
]);

$this->actingAs($admin, config('possession.admin_guard'));

Possession::possess($user);

// Set an unrelated application session state during impersonation
Session::put('checkout_step', 2);

Possession::unpossess();

// Assert session state is preserved
$this->assertTrue(Session::has('checkout_step'));
$this->assertEquals(2, Session::get('checkout_step'));
}
}

class SessionFlushAdminStub extends Authenticatable
{
use ImpersonatesUsers;
protected $table = 'users';
protected $guarded = [];
public function canPossess(): bool { return true; }
}

class SessionFlushUserStub extends Authenticatable
{
use ImpersonatesUsers;
protected $table = 'users';
protected $guarded = [];
public function canBePossessed(): bool { return true; }
}