Authentication API

Authentication API

This page documents the internal middleware-based authorization used across the NMS Prime web application. If you are looking for how to authenticate against the REST API from an external system, see NMS Prime API.

1. General

NMS Prime uses middlewares to restrict access to certain parts of the system. Two types of middleware secure the routes, both provided by Laravel:

  • web — establishes the session and verifies that the user is authenticated.

  • can — checks that the authenticated user is authorized for the requested action on a given model (for example can:view, can:create, can:update, can:delete).

To learn more about these middlewares, see the official Laravel documentation.

1.1. Generic routes with middleware

Running the php artisan route:list command prints a table of all routing information, including a Middleware column that shows which middlewares protect each route:

[nmsprime@nmsprime-demo nmsprime]$ php artisan route:list +--------+----------+-------------------------------+------------------+--------------------------------------------------------------+----------------------------------------------------+ | Domain | Method | URI | Name | Action | Middleware | +--------+----------+-------------------------------+------------------+--------------------------------------------------------------+----------------------------------------------------+ ... | | GET|HEAD | admin/Contract | Contract.index | Modules\ProvBase\Http\Controllers\ContractController@index | web,can:view,Modules\ProvBase\Entities\Contract | | | POST | admin/Contract | Contract.store | Modules\ProvBase\Http\Controllers\ContractController@store | web,can:create,Modules\ProvBase\Entities\Contract | | | GET|HEAD | admin/Contract/create | Contract.create | Modules\ProvBase\Http\Controllers\ContractController@create | web,can:create,Modules\ProvBase\Entities\Contract | | | PUT | admin/Contract/{Contract} | Contract.update | Modules\ProvBase\Http\Controllers\ContractController@update | web,can:update,Modules\ProvBase\Entities\Contract | | | GET|HEAD | admin/Contract/{Contract} | Contract.edit | Modules\ProvBase\Http\Controllers\ContractController@edit | web,can:view,Modules\ProvBase\Entities\Contract | | | DELETE | admin/Contract/{Contract} | Contract.destroy | Modules\ProvBase\Http\Controllers\ContractController@destroy | web,can:delete,Modules\ProvBase\Entities\Contract | | | PATCH | admin/Contract/{Contract} | Contract.update | Modules\ProvBase\Http\Controllers\ContractController@update | web,can:update,Modules\ProvBase\Entities\Contract | | | GET|HEAD | admin/Contract/{Contract}/log | Contract.guilog | \App\Http\Controllers\GuiLogController@filter | web,can:view,Modules\ProvBase\Entities\Contract | ...

2. Workflows

2.1. Middleware authentication checking

The following diagram shows how an incoming request passes through the authentication and authorization middlewares before reaching the controller:

2.2. Login workflow

Note that there are two AuthControllers, selected by the route that is used:

The routes define which controller is used. This is standard Laravel behaviour — no NMS Prime magic involved.