3
0
mirror of https://github.com/snipe/snipe-it.git synced 2026-08-18 11:15:42 +00:00

Unlock button in demo mode but don’t persist state

This commit is contained in:
snipe
2026-08-07 15:51:22 +01:00
parent 707580080d
commit 83a05e9383
3 changed files with 62 additions and 2 deletions

View File

@ -56,7 +56,12 @@ class ResetDemoSettings extends Command
$settings->label2_2d_type = 'QRCODE';
$settings->default_currency = 'USD';
$settings->brand = 2;
$settings->ldap_enabled = 0;
// Enabled so the wizard's return-visitor branch unlocks all 5
// steps for demo visitors and they can jump straight to the
// step-3 Test Find User preview against the seeded Forumsys
// config. Safe on the demo because LoginController skips the
// LDAP auth branch when config('app.lock_passwords') is on.
$settings->ldap_enabled = '1';
$settings->full_multiple_companies_support = 0;
$settings->label2_1d_type = 'C128';
$settings->email_domain = 'snipeitapp.com';

View File

@ -78,6 +78,24 @@ class LdapSettings extends Component
// finishWizard so back-nav doesn't retrigger the animation.
public ?int $justCompletedStep = null;
// Read-only lock. Set from config('app.lock_passwords') in mount()
// and blade uses it to render every wire:model input with the
// `readonly` / `disabled` attribute so demo visitors can't retype
// real LDAP creds into the wizard. Server-side enforcement lives
// in updated(), which reverts any prop mutation back to the
// persisted Setting values (defense against a caller that fakes
// wire:model updates around the disabled UI).
public bool $isReadOnly = false;
// Properties that stay editable even when isReadOnly is on. The
// sample-username field on step 3 has to remain writable so the
// Test Find User preview still works, which is the one wizard
// interaction we do want demo visitors to exercise.
private const READ_ONLY_ALLOWED_PROPS = [
'currentStep',
'test_sample_username',
];
// Step 1: Connection
public bool $ldap_enabled = false;
@ -185,6 +203,7 @@ class LdapSettings extends Component
public function mount(): void
{
$this->isReadOnly = (bool) config('app.lock_passwords');
$this->hydrateFromPersisted();
// Restore in-flight wizard progress from the session so a page
@ -209,6 +228,17 @@ class LdapSettings extends Component
}
}
// Demo mode unlocks the wizard independent of ldap_enabled.
// The save/advance methods are gated shut by lock_passwords
// so a visitor with ldap_enabled=false would otherwise be
// trapped on step 1 with no way to reach the Test Find User
// preview on step 3. Unlocking the stepper here lets them
// jump to any step. Fields stay locked via isReadOnly /
// updated() enforcement.
if ($this->isReadOnly) {
$this->highestStepReached = 5;
}
// Clamp against total step count in case a session pointer
// was seeded when the wizard had a different step layout.
$this->highestStepReached = min($this->highestStepReached, 5);
@ -313,7 +343,18 @@ class LdapSettings extends Component
public function saveAndAdvance()
{
// Demo mode: nothing to save (isReadOnly + updated() lock the
// fields to seeded values), but visitors still want to walk
// the wizard forward step by step to see each screen. Skip
// validation / network test / persist and just advance. The
// per-step Test Bind / Test Find User buttons on individual
// steps remain available for anyone who wants to fire a live
// request against the seeded Forumsys config.
if (config('app.lock_passwords')) {
if ($this->currentStep < 5) {
$this->goToStep($this->currentStep + 1);
}
return null;
}
@ -1365,6 +1406,20 @@ class LdapSettings extends Component
public function updated(string $property): void
{
// Read-only lock: in demo mode any mutation to a persisted
// LDAP config field gets reverted to the seeded Setting value
// before the rest of the updated() logic runs. Server-side
// enforcement, so a client that fakes wire:model updates
// around the UI's readonly / disabled attributes still can't
// get modified creds into a Test Bind / Test Find User call.
// test_sample_username stays writable so the Look Up preview
// still works.
if ($this->isReadOnly && ! in_array($property, self::READ_ONLY_ALLOWED_PROPS, true)) {
$this->hydrateFromPersisted();
return;
}
// Trim string values on assignment so pasted-with-whitespace
// inputs get normalized both in the visible field and in the
// saved config. Without this a leading space on ldap_server

View File

@ -814,7 +814,7 @@
wire:loading.attr="disabled"
wire:target="saveAndAdvance"
class="btn btn-primary"
@disabled(config('app.lock_passwords') || ! $this->canAdvance)
@disabled(! config('app.lock_passwords') && ! $this->canAdvance)
>
<span wire:loading.remove wire:target="saveAndAdvance">
@if ($currentStep === 4)