]> BookStack Code Mirror - bookstack/blob - routes/web.php
Add optional OIDC avatar fetching from the “picture” claim
[bookstack] / routes / web.php
1 <?php
2
3 use BookStack\Access\Controllers as AccessControllers;
4 use BookStack\Activity\Controllers as ActivityControllers;
5 use BookStack\Api\ApiDocsController;
6 use BookStack\Api\UserApiTokenController;
7 use BookStack\App\HomeController;
8 use BookStack\App\MetaController;
9 use BookStack\Entities\Controllers as EntityControllers;
10 use BookStack\Exports\Controllers as ExportControllers;
11 use BookStack\Http\Middleware\VerifyCsrfToken;
12 use BookStack\Permissions\PermissionsController;
13 use BookStack\References\ReferenceController;
14 use BookStack\Search\SearchController;
15 use BookStack\Settings as SettingControllers;
16 use BookStack\Theming\ThemeController;
17 use BookStack\Uploads\Controllers as UploadControllers;
18 use BookStack\Users\Controllers as UserControllers;
19 use Illuminate\Session\Middleware\StartSession;
20 use Illuminate\Support\Facades\Route;
21 use Illuminate\View\Middleware\ShareErrorsFromSession;
22
23 // Status & Meta routes
24 Route::get('/status', [SettingControllers\StatusController::class, 'show']);
25 Route::get('/robots.txt', [MetaController::class, 'robots']);
26 Route::get('/favicon.ico', [MetaController::class, 'favicon']);
27 Route::get('/manifest.json', [MetaController::class, 'pwaManifest']);
28 Route::get('/licenses', [MetaController::class, 'licenses']);
29 Route::get('/opensearch.xml', [MetaController::class, 'opensearch']);
30
31 // Authenticated routes...
32 Route::middleware('auth')->group(function () {
33
34     // Secure images routing
35     Route::get('/uploads/images/{path}', [UploadControllers\ImageController::class, 'showImage'])
36         ->where('path', '.*$');
37
38     // API docs routes
39     Route::get('/api', [ApiDocsController::class, 'redirect']);
40     Route::get('/api/docs', [ApiDocsController::class, 'display']);
41
42     Route::get('/pages/recently-updated', [EntityControllers\PageController::class, 'showRecentlyUpdated']);
43
44     // Shelves
45     Route::get('/create-shelf', [EntityControllers\BookshelfController::class, 'create']);
46     Route::get('/shelves/', [EntityControllers\BookshelfController::class, 'index']);
47     Route::post('/shelves/', [EntityControllers\BookshelfController::class, 'store']);
48     Route::get('/shelves/{slug}/edit', [EntityControllers\BookshelfController::class, 'edit']);
49     Route::get('/shelves/{slug}/delete', [EntityControllers\BookshelfController::class, 'showDelete']);
50     Route::get('/shelves/{slug}', [EntityControllers\BookshelfController::class, 'show']);
51     Route::put('/shelves/{slug}', [EntityControllers\BookshelfController::class, 'update']);
52     Route::delete('/shelves/{slug}', [EntityControllers\BookshelfController::class, 'destroy']);
53     Route::get('/shelves/{slug}/permissions', [PermissionsController::class, 'showForShelf']);
54     Route::put('/shelves/{slug}/permissions', [PermissionsController::class, 'updateForShelf']);
55     Route::post('/shelves/{slug}/copy-permissions', [PermissionsController::class, 'copyShelfPermissionsToBooks']);
56     Route::get('/shelves/{slug}/references', [ReferenceController::class, 'shelf']);
57
58     // Book Creation
59     Route::get('/shelves/{shelfSlug}/create-book', [EntityControllers\BookController::class, 'create']);
60     Route::post('/shelves/{shelfSlug}/create-book', [EntityControllers\BookController::class, 'store']);
61     Route::get('/create-book', [EntityControllers\BookController::class, 'create']);
62
63     // Books
64     Route::get('/books/', [EntityControllers\BookController::class, 'index']);
65     Route::post('/books/', [EntityControllers\BookController::class, 'store']);
66     Route::get('/books/{slug}/edit', [EntityControllers\BookController::class, 'edit']);
67     Route::put('/books/{slug}', [EntityControllers\BookController::class, 'update']);
68     Route::delete('/books/{id}', [EntityControllers\BookController::class, 'destroy']);
69     Route::get('/books/{slug}/sort-item', [EntityControllers\BookSortController::class, 'showItem']);
70     Route::get('/books/{slug}', [EntityControllers\BookController::class, 'show']);
71     Route::get('/books/{bookSlug}/permissions', [PermissionsController::class, 'showForBook']);
72     Route::put('/books/{bookSlug}/permissions', [PermissionsController::class, 'updateForBook']);
73     Route::get('/books/{slug}/delete', [EntityControllers\BookController::class, 'showDelete']);
74     Route::get('/books/{bookSlug}/copy', [EntityControllers\BookController::class, 'showCopy']);
75     Route::post('/books/{bookSlug}/copy', [EntityControllers\BookController::class, 'copy']);
76     Route::post('/books/{bookSlug}/convert-to-shelf', [EntityControllers\BookController::class, 'convertToShelf']);
77     Route::get('/books/{bookSlug}/sort', [EntityControllers\BookSortController::class, 'show']);
78     Route::put('/books/{bookSlug}/sort', [EntityControllers\BookSortController::class, 'update']);
79     Route::get('/books/{slug}/references', [ReferenceController::class, 'book']);
80     Route::get('/books/{bookSlug}/export/html', [ExportControllers\BookExportController::class, 'html']);
81     Route::get('/books/{bookSlug}/export/pdf', [ExportControllers\BookExportController::class, 'pdf']);
82     Route::get('/books/{bookSlug}/export/markdown', [ExportControllers\BookExportController::class, 'markdown']);
83     Route::get('/books/{bookSlug}/export/zip', [ExportControllers\BookExportController::class, 'zip']);
84     Route::get('/books/{bookSlug}/export/plaintext', [ExportControllers\BookExportController::class, 'plainText']);
85
86     // Pages
87     Route::get('/books/{bookSlug}/create-page', [EntityControllers\PageController::class, 'create']);
88     Route::post('/books/{bookSlug}/create-guest-page', [EntityControllers\PageController::class, 'createAsGuest']);
89     Route::get('/books/{bookSlug}/draft/{pageId}', [EntityControllers\PageController::class, 'editDraft']);
90     Route::post('/books/{bookSlug}/draft/{pageId}', [EntityControllers\PageController::class, 'store']);
91     Route::get('/books/{bookSlug}/page/{pageSlug}', [EntityControllers\PageController::class, 'show']);
92     Route::get('/books/{bookSlug}/page/{pageSlug}/export/pdf', [ExportControllers\PageExportController::class, 'pdf']);
93     Route::get('/books/{bookSlug}/page/{pageSlug}/export/html', [ExportControllers\PageExportController::class, 'html']);
94     Route::get('/books/{bookSlug}/page/{pageSlug}/export/markdown', [ExportControllers\PageExportController::class, 'markdown']);
95     Route::get('/books/{bookSlug}/page/{pageSlug}/export/plaintext', [ExportControllers\PageExportController::class, 'plainText']);
96     Route::get('/books/{bookSlug}/page/{pageSlug}/export/zip', [ExportControllers\PageExportController::class, 'zip']);
97     Route::get('/books/{bookSlug}/page/{pageSlug}/edit', [EntityControllers\PageController::class, 'edit']);
98     Route::get('/books/{bookSlug}/page/{pageSlug}/move', [EntityControllers\PageController::class, 'showMove']);
99     Route::put('/books/{bookSlug}/page/{pageSlug}/move', [EntityControllers\PageController::class, 'move']);
100     Route::get('/books/{bookSlug}/page/{pageSlug}/copy', [EntityControllers\PageController::class, 'showCopy']);
101     Route::post('/books/{bookSlug}/page/{pageSlug}/copy', [EntityControllers\PageController::class, 'copy']);
102     Route::get('/books/{bookSlug}/page/{pageSlug}/delete', [EntityControllers\PageController::class, 'showDelete']);
103     Route::get('/books/{bookSlug}/draft/{pageId}/delete', [EntityControllers\PageController::class, 'showDeleteDraft']);
104     Route::get('/books/{bookSlug}/page/{pageSlug}/permissions', [PermissionsController::class, 'showForPage']);
105     Route::put('/books/{bookSlug}/page/{pageSlug}/permissions', [PermissionsController::class, 'updateForPage']);
106     Route::get('/books/{bookSlug}/page/{pageSlug}/references', [ReferenceController::class, 'page']);
107     Route::put('/books/{bookSlug}/page/{pageSlug}', [EntityControllers\PageController::class, 'update']);
108     Route::delete('/books/{bookSlug}/page/{pageSlug}', [EntityControllers\PageController::class, 'destroy']);
109     Route::delete('/books/{bookSlug}/draft/{pageId}', [EntityControllers\PageController::class, 'destroyDraft']);
110
111     // Revisions
112     Route::get('/books/{bookSlug}/page/{pageSlug}/revisions', [EntityControllers\PageRevisionController::class, 'index']);
113     Route::get('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}', [EntityControllers\PageRevisionController::class, 'show']);
114     Route::get('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}/changes', [EntityControllers\PageRevisionController::class, 'changes']);
115     Route::put('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}/restore', [EntityControllers\PageRevisionController::class, 'restore']);
116     Route::delete('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}/delete', [EntityControllers\PageRevisionController::class, 'destroy']);
117     Route::delete('/page-revisions/user-drafts/{pageId}', [EntityControllers\PageRevisionController::class, 'destroyUserDraft']);
118
119     // Chapters
120     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/create-page', [EntityControllers\PageController::class, 'create']);
121     Route::post('/books/{bookSlug}/chapter/{chapterSlug}/create-guest-page', [EntityControllers\PageController::class, 'createAsGuest']);
122     Route::get('/books/{bookSlug}/create-chapter', [EntityControllers\ChapterController::class, 'create']);
123     Route::post('/books/{bookSlug}/create-chapter', [EntityControllers\ChapterController::class, 'store']);
124     Route::get('/books/{bookSlug}/chapter/{chapterSlug}', [EntityControllers\ChapterController::class, 'show']);
125     Route::put('/books/{bookSlug}/chapter/{chapterSlug}', [EntityControllers\ChapterController::class, 'update']);
126     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/move', [EntityControllers\ChapterController::class, 'showMove']);
127     Route::put('/books/{bookSlug}/chapter/{chapterSlug}/move', [EntityControllers\ChapterController::class, 'move']);
128     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/copy', [EntityControllers\ChapterController::class, 'showCopy']);
129     Route::post('/books/{bookSlug}/chapter/{chapterSlug}/copy', [EntityControllers\ChapterController::class, 'copy']);
130     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/edit', [EntityControllers\ChapterController::class, 'edit']);
131     Route::post('/books/{bookSlug}/chapter/{chapterSlug}/convert-to-book', [EntityControllers\ChapterController::class, 'convertToBook']);
132     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/permissions', [PermissionsController::class, 'showForChapter']);
133     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/pdf', [ExportControllers\ChapterExportController::class, 'pdf']);
134     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/html', [ExportControllers\ChapterExportController::class, 'html']);
135     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/markdown', [ExportControllers\ChapterExportController::class, 'markdown']);
136     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/plaintext', [ExportControllers\ChapterExportController::class, 'plainText']);
137     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/zip', [ExportControllers\ChapterExportController::class, 'zip']);
138     Route::put('/books/{bookSlug}/chapter/{chapterSlug}/permissions', [PermissionsController::class, 'updateForChapter']);
139     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/references', [ReferenceController::class, 'chapter']);
140     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/delete', [EntityControllers\ChapterController::class, 'showDelete']);
141     Route::delete('/books/{bookSlug}/chapter/{chapterSlug}', [EntityControllers\ChapterController::class, 'destroy']);
142
143     // User Profile routes
144     Route::get('/user/{slug}', [UserControllers\UserProfileController::class, 'show']);
145
146     // Image routes
147     Route::get('/images/gallery', [UploadControllers\GalleryImageController::class, 'list']);
148     Route::post('/images/gallery', [UploadControllers\GalleryImageController::class, 'create']);
149     Route::get('/images/drawio', [UploadControllers\DrawioImageController::class, 'list']);
150     Route::get('/images/drawio/base64/{id}', [UploadControllers\DrawioImageController::class, 'getAsBase64']);
151     Route::post('/images/drawio', [UploadControllers\DrawioImageController::class, 'create']);
152     Route::get('/images/edit/{id}', [UploadControllers\ImageController::class, 'edit']);
153     Route::put('/images/{id}/file', [UploadControllers\ImageController::class, 'updateFile']);
154     Route::put('/images/{id}/rebuild-thumbnails', [UploadControllers\ImageController::class, 'rebuildThumbnails']);
155     Route::put('/images/{id}', [UploadControllers\ImageController::class, 'update']);
156     Route::delete('/images/{id}', [UploadControllers\ImageController::class, 'destroy']);
157
158     // Attachments routes
159     Route::get('/attachments/{id}', [UploadControllers\AttachmentController::class, 'get']);
160     Route::post('/attachments/upload', [UploadControllers\AttachmentController::class, 'upload']);
161     Route::post('/attachments/upload/{id}', [UploadControllers\AttachmentController::class, 'uploadUpdate']);
162     Route::post('/attachments/link', [UploadControllers\AttachmentController::class, 'attachLink']);
163     Route::put('/attachments/{id}', [UploadControllers\AttachmentController::class, 'update']);
164     Route::get('/attachments/edit/{id}', [UploadControllers\AttachmentController::class, 'getUpdateForm']);
165     Route::get('/attachments/get/page/{pageId}', [UploadControllers\AttachmentController::class, 'listForPage']);
166     Route::put('/attachments/sort/page/{pageId}', [UploadControllers\AttachmentController::class, 'sortForPage']);
167     Route::delete('/attachments/{id}', [UploadControllers\AttachmentController::class, 'delete']);
168
169     // AJAX routes
170     Route::put('/ajax/page/{id}/save-draft', [EntityControllers\PageController::class, 'saveDraft']);
171     Route::get('/ajax/page/{id}', [EntityControllers\PageController::class, 'getPageAjax']);
172     Route::delete('/ajax/page/{id}', [EntityControllers\PageController::class, 'ajaxDestroy']);
173
174     // Tag routes
175     Route::get('/tags', [ActivityControllers\TagController::class, 'index']);
176     Route::get('/ajax/tags/suggest/names', [ActivityControllers\TagController::class, 'getNameSuggestions']);
177     Route::get('/ajax/tags/suggest/values', [ActivityControllers\TagController::class, 'getValueSuggestions']);
178
179     // Comments
180     Route::post('/comment/{pageId}', [ActivityControllers\CommentController::class, 'savePageComment']);
181     Route::put('/comment/{id}', [ActivityControllers\CommentController::class, 'update']);
182     Route::delete('/comment/{id}', [ActivityControllers\CommentController::class, 'destroy']);
183
184     // Links
185     Route::get('/link/{id}', [EntityControllers\PageController::class, 'redirectFromLink']);
186
187     // Search
188     Route::get('/search', [SearchController::class, 'search']);
189     Route::get('/search/book/{bookId}', [SearchController::class, 'searchBook']);
190     Route::get('/search/chapter/{bookId}', [SearchController::class, 'searchChapter']);
191     Route::get('/search/entity/siblings', [SearchController::class, 'searchSiblings']);
192     Route::get('/search/entity-selector', [SearchController::class, 'searchForSelector']);
193     Route::get('/search/entity-selector-templates', [SearchController::class, 'templatesForSelector']);
194     Route::get('/search/suggest', [SearchController::class, 'searchSuggestions']);
195
196     // User Search
197     Route::get('/search/users/select', [UserControllers\UserSearchController::class, 'forSelect']);
198
199     // Template System
200     Route::get('/templates', [EntityControllers\PageTemplateController::class, 'list']);
201     Route::get('/templates/{templateId}', [EntityControllers\PageTemplateController::class, 'get']);
202
203     // Favourites
204     Route::get('/favourites', [ActivityControllers\FavouriteController::class, 'index']);
205     Route::post('/favourites/add', [ActivityControllers\FavouriteController::class, 'add']);
206     Route::post('/favourites/remove', [ActivityControllers\FavouriteController::class, 'remove']);
207
208     // Watching
209     Route::put('/watching/update', [ActivityControllers\WatchController::class, 'update']);
210
211     // Importing
212     Route::get('/import', [ExportControllers\ImportController::class, 'start']);
213     Route::post('/import', [ExportControllers\ImportController::class, 'upload']);
214     Route::get('/import/{id}', [ExportControllers\ImportController::class, 'show']);
215     Route::post('/import/{id}', [ExportControllers\ImportController::class, 'run']);
216     Route::delete('/import/{id}', [ExportControllers\ImportController::class, 'delete']);
217
218     // Other Pages
219     Route::get('/', [HomeController::class, 'index']);
220     Route::get('/home', [HomeController::class, 'index']);
221
222     // Permissions
223     Route::get('/permissions/form-row/{entityType}/{roleId}', [PermissionsController::class, 'formRowForRole']);
224
225     // Maintenance
226     Route::get('/settings/maintenance', [SettingControllers\MaintenanceController::class, 'index']);
227     Route::delete('/settings/maintenance/cleanup-images', [SettingControllers\MaintenanceController::class, 'cleanupImages']);
228     Route::post('/settings/maintenance/send-test-email', [SettingControllers\MaintenanceController::class, 'sendTestEmail']);
229     Route::post('/settings/maintenance/regenerate-references', [SettingControllers\MaintenanceController::class, 'regenerateReferences']);
230
231     // Recycle Bin
232     Route::get('/settings/recycle-bin', [EntityControllers\RecycleBinController::class, 'index']);
233     Route::post('/settings/recycle-bin/empty', [EntityControllers\RecycleBinController::class, 'empty']);
234     Route::get('/settings/recycle-bin/{id}/destroy', [EntityControllers\RecycleBinController::class, 'showDestroy']);
235     Route::delete('/settings/recycle-bin/{id}', [EntityControllers\RecycleBinController::class, 'destroy']);
236     Route::get('/settings/recycle-bin/{id}/restore', [EntityControllers\RecycleBinController::class, 'showRestore']);
237     Route::post('/settings/recycle-bin/{id}/restore', [EntityControllers\RecycleBinController::class, 'restore']);
238
239     // Audit Log
240     Route::get('/settings/audit', [ActivityControllers\AuditLogController::class, 'index']);
241
242     // Users
243     Route::get('/settings/users', [UserControllers\UserController::class, 'index']);
244     Route::get('/settings/users/create', [UserControllers\UserController::class, 'create']);
245     Route::get('/settings/users/{id}/delete', [UserControllers\UserController::class, 'delete']);
246     Route::post('/settings/users/create', [UserControllers\UserController::class, 'store']);
247     Route::get('/settings/users/{id}', [UserControllers\UserController::class, 'edit']);
248     Route::put('/settings/users/{id}', [UserControllers\UserController::class, 'update']);
249     Route::delete('/settings/users/{id}', [UserControllers\UserController::class, 'destroy']);
250
251     // User Account
252     Route::get('/my-account', [UserControllers\UserAccountController::class, 'redirect']);
253     Route::get('/my-account/profile', [UserControllers\UserAccountController::class, 'showProfile']);
254     Route::put('/my-account/profile', [UserControllers\UserAccountController::class, 'updateProfile']);
255     Route::get('/my-account/shortcuts', [UserControllers\UserAccountController::class, 'showShortcuts']);
256     Route::put('/my-account/shortcuts', [UserControllers\UserAccountController::class, 'updateShortcuts']);
257     Route::get('/my-account/notifications', [UserControllers\UserAccountController::class, 'showNotifications']);
258     Route::put('/my-account/notifications', [UserControllers\UserAccountController::class, 'updateNotifications']);
259     Route::get('/my-account/auth', [UserControllers\UserAccountController::class, 'showAuth']);
260     Route::put('/my-account/auth/password', [UserControllers\UserAccountController::class, 'updatePassword']);
261     Route::get('/my-account/delete', [UserControllers\UserAccountController::class, 'delete']);
262     Route::delete('/my-account', [UserControllers\UserAccountController::class, 'destroy']);
263
264     // User Preference Endpoints
265     Route::patch('/preferences/change-view/{type}', [UserControllers\UserPreferencesController::class, 'changeView']);
266     Route::patch('/preferences/change-sort/{type}', [UserControllers\UserPreferencesController::class, 'changeSort']);
267     Route::patch('/preferences/change-expansion/{type}', [UserControllers\UserPreferencesController::class, 'changeExpansion']);
268     Route::patch('/preferences/toggle-dark-mode', [UserControllers\UserPreferencesController::class, 'toggleDarkMode']);
269     Route::patch('/preferences/update-code-language-favourite', [UserControllers\UserPreferencesController::class, 'updateCodeLanguageFavourite']);
270
271     // User API Tokens
272     Route::get('/api-tokens/{userId}/create', [UserApiTokenController::class, 'create']);
273     Route::post('/api-tokens/{userId}/create', [UserApiTokenController::class, 'store']);
274     Route::get('/api-tokens/{userId}/{tokenId}', [UserApiTokenController::class, 'edit']);
275     Route::put('/api-tokens/{userId}/{tokenId}', [UserApiTokenController::class, 'update']);
276     Route::get('/api-tokens/{userId}/{tokenId}/delete', [UserApiTokenController::class, 'delete']);
277     Route::delete('/api-tokens/{userId}/{tokenId}', [UserApiTokenController::class, 'destroy']);
278
279     // Roles
280     Route::get('/settings/roles', [UserControllers\RoleController::class, 'index']);
281     Route::get('/settings/roles/new', [UserControllers\RoleController::class, 'create']);
282     Route::post('/settings/roles/new', [UserControllers\RoleController::class, 'store']);
283     Route::get('/settings/roles/delete/{id}', [UserControllers\RoleController::class, 'showDelete']);
284     Route::delete('/settings/roles/delete/{id}', [UserControllers\RoleController::class, 'delete']);
285     Route::get('/settings/roles/{id}', [UserControllers\RoleController::class, 'edit']);
286     Route::put('/settings/roles/{id}', [UserControllers\RoleController::class, 'update']);
287
288     // Webhooks
289     Route::get('/settings/webhooks', [ActivityControllers\WebhookController::class, 'index']);
290     Route::get('/settings/webhooks/create', [ActivityControllers\WebhookController::class, 'create']);
291     Route::post('/settings/webhooks/create', [ActivityControllers\WebhookController::class, 'store']);
292     Route::get('/settings/webhooks/{id}', [ActivityControllers\WebhookController::class, 'edit']);
293     Route::put('/settings/webhooks/{id}', [ActivityControllers\WebhookController::class, 'update']);
294     Route::get('/settings/webhooks/{id}/delete', [ActivityControllers\WebhookController::class, 'delete']);
295     Route::delete('/settings/webhooks/{id}', [ActivityControllers\WebhookController::class, 'destroy']);
296
297     // Settings
298     Route::get('/settings', [SettingControllers\SettingController::class, 'index'])->name('settings');
299     Route::get('/settings/{category}', [SettingControllers\SettingController::class, 'category'])->name('settings.category');
300     Route::post('/settings/{category}', [SettingControllers\SettingController::class, 'update']);
301 });
302
303 // MFA routes
304 Route::middleware('mfa-setup')->group(function () {
305     Route::get('/mfa/setup', [AccessControllers\MfaController::class, 'setup']);
306     Route::get('/mfa/totp/generate', [AccessControllers\MfaTotpController::class, 'generate']);
307     Route::post('/mfa/totp/confirm', [AccessControllers\MfaTotpController::class, 'confirm']);
308     Route::get('/mfa/backup_codes/generate', [AccessControllers\MfaBackupCodesController::class, 'generate']);
309     Route::post('/mfa/backup_codes/confirm', [AccessControllers\MfaBackupCodesController::class, 'confirm']);
310 });
311 Route::middleware('guest')->group(function () {
312     Route::get('/mfa/verify', [AccessControllers\MfaController::class, 'verify']);
313     Route::post('/mfa/totp/verify', [AccessControllers\MfaTotpController::class, 'verify']);
314     Route::post('/mfa/backup_codes/verify', [AccessControllers\MfaBackupCodesController::class, 'verify']);
315 });
316 Route::delete('/mfa/{method}/remove', [AccessControllers\MfaController::class, 'remove'])->middleware('auth');
317
318 // Social auth routes
319 Route::get('/login/service/{socialDriver}', [AccessControllers\SocialController::class, 'login']);
320 Route::get('/login/service/{socialDriver}/callback', [AccessControllers\SocialController::class, 'callback']);
321 Route::post('/login/service/{socialDriver}/detach', [AccessControllers\SocialController::class, 'detach'])->middleware('auth');
322 Route::get('/register/service/{socialDriver}', [AccessControllers\SocialController::class, 'register']);
323
324 // Login/Logout routes
325 Route::get('/login', [AccessControllers\LoginController::class, 'getLogin']);
326 Route::post('/login', [AccessControllers\LoginController::class, 'login']);
327 Route::post('/logout', [AccessControllers\LoginController::class, 'logout']);
328 Route::get('/register', [AccessControllers\RegisterController::class, 'getRegister']);
329 Route::get('/register/confirm', [AccessControllers\ConfirmEmailController::class, 'show']);
330 Route::get('/register/confirm/awaiting', [AccessControllers\ConfirmEmailController::class, 'showAwaiting']);
331 Route::post('/register/confirm/resend', [AccessControllers\ConfirmEmailController::class, 'resend']);
332 Route::get('/register/confirm/{token}', [AccessControllers\ConfirmEmailController::class, 'showAcceptForm']);
333 Route::post('/register/confirm/accept', [AccessControllers\ConfirmEmailController::class, 'confirm'])->middleware('throttle:public');
334 Route::post('/register', [AccessControllers\RegisterController::class, 'postRegister'])->middleware('throttle:public');
335
336 // SAML routes
337 Route::post('/saml2/login', [AccessControllers\Saml2Controller::class, 'login']);
338 Route::post('/saml2/logout', [AccessControllers\Saml2Controller::class, 'logout']);
339 Route::get('/saml2/metadata', [AccessControllers\Saml2Controller::class, 'metadata']);
340 Route::get('/saml2/sls', [AccessControllers\Saml2Controller::class, 'sls']);
341 Route::post('/saml2/acs', [AccessControllers\Saml2Controller::class, 'startAcs'])->withoutMiddleware([
342     StartSession::class,
343     ShareErrorsFromSession::class,
344     VerifyCsrfToken::class,
345 ]);
346 Route::get('/saml2/acs', [AccessControllers\Saml2Controller::class, 'processAcs']);
347
348 // OIDC routes
349 Route::post('/oidc/login', [AccessControllers\OidcController::class, 'login']);
350 Route::get('/oidc/callback', [AccessControllers\OidcController::class, 'callback']);
351 Route::post('/oidc/logout', [AccessControllers\OidcController::class, 'logout']);
352
353 // User invitation routes
354 Route::get('/register/invite/{token}', [AccessControllers\UserInviteController::class, 'showSetPassword'])->middleware('throttle:public');
355 Route::post('/register/invite/{token}', [AccessControllers\UserInviteController::class, 'setPassword'])->middleware('throttle:public');
356
357 // Password reset link request routes
358 Route::get('/password/email', [AccessControllers\ForgotPasswordController::class, 'showLinkRequestForm']);
359 Route::post('/password/email', [AccessControllers\ForgotPasswordController::class, 'sendResetLinkEmail'])->middleware('throttle:public');
360
361 // Password reset routes
362 Route::get('/password/reset/{token}', [AccessControllers\ResetPasswordController::class, 'showResetForm']);
363 Route::post('/password/reset', [AccessControllers\ResetPasswordController::class, 'reset'])->middleware('throttle:public');
364
365 // Help & Info routes
366 Route::view('/help/tinymce', 'help.tinymce');
367 Route::view('/help/wysiwyg', 'help.wysiwyg');
368
369 // Theme Routes
370 Route::get('/theme/{theme}/{path}', [ThemeController::class, 'publicFile'])
371     ->where('path', '.*$');
372
373 Route::fallback([MetaController::class, 'notFound'])->name('fallback');