Enhance JWT Authentication Middleware and Configuration

- Updated the `AuthenticateJWT.php` middleware to conditionally skip IP and User Agent validation based on a new configuration setting, improving flexibility for users with dynamic IPs.
- Added a new configuration option `jwt_skip_ip_ua_validation` in `app.php` to control the validation behavior, allowing it to be set via the environment file.
- Updated documentation in `environment-variables.mdx` to include the new configuration option, ensuring users are informed about its purpose and usage.

These changes enhance the JWT authentication process by providing an option to bypass IP and User Agent validation, improving usability for self-hosted users.
This commit is contained in:
Julien Nahum
2025-05-07 08:26:33 +02:00
parent f2f5213d46
commit 6b03808d36
3 changed files with 19 additions and 0 deletions

View File

@@ -68,6 +68,19 @@ return [
'front_url' => env('FRONT_URL', null),
'front_api_secret' => env('FRONT_API_SECRET', null),
/*
|--------------------------------------------------------------------------
| JWT IP and User Agent Validation
|--------------------------------------------------------------------------
|
| This value determines if the IP and User Agent validation for JWT tokens
| should be skipped. This can be useful for self-hosting users with dynamic IPs.
| Set this in your ".env" file.
|
*/
'jwt_skip_ip_ua_validation' => env('JWT_SKIP_IP_UA_VALIDATION', false),
/*
|--------------------------------------------------------------------------
| Application Timezone