Repository navigation
Conversation
The package clears impersonation on every `Login`/`Logout` event regardless of which guard fired it. In apps that share a single session across multiple guards (e.g. an admin guard alongside a separate customer/storefront guard), an unrelated guard authenticating — a customer logging in on the storefront, or a "remember me" recaller silently re-authenticating on a GET — tears down an active admin impersonation. The impersonator's own session key is left intact, so they stay authenticated *as* the impersonated user while `isImpersonating()` flips to false: no banner, no way to leave. Only end the impersonation when the auth event belongs to a guard involved in the impersonation (the impersonator's guard or the one being used). Behaviour is unchanged for single-guard apps and when not impersonating. Adds tests covering both the unrelated-guard (preserve) and impersonator-guard (clear) paths. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
FilamentImpersonateServiceProvider::registeringPackage()clears impersonation on everyLogin/Logoutevent, ignoring which guard fired it:In apps that share a single session across multiple guards (e.g. an admin guard alongside a separate
customer/storefront guard on the same domain), this is unsafe. While an admin is impersonating, an unrelated guard authenticating — a customer logging in on the storefront, or a "remember me" recaller silently re-authenticating on a plain GET — fires aLogin/Logoutand tears the impersonation down.The impersonator's own session login key is left untouched, so they remain authenticated as the impersonated user, but
isImpersonating()now returnsfalse: the banner disappears and there's no way to leave. The admin is silently stuck as the impersonated user.Fix
Only end the impersonation when the auth event belongs to a guard involved in the impersonation (the impersonator's guard, or the guard being used):
Backward compatibility
Impersonation::clear()exactly as before (e.g. clearing stray keys on a fresh login).Tests
Adds
tests/ImpersonationClearOnAuthEventTest.phpcovering both paths (unrelated guard preserves; impersonator guard clears; not-impersonating unchanged). Full suite passes locally (135 passed).