addOption('email', null, InputOption::VALUE_REQUIRED, 'Email of an existing user to mint a token for') ->addOption('name', null, InputOption::VALUE_OPTIONAL, 'Token name (logged on the row, useful for traceability)', 'cli-issued') ->addOption('quiet-output', null, InputOption::VALUE_NONE, 'Print only the token (no decoration). Useful for shell capture.'); } protected function execute(InputInterface $input, OutputInterface $output): int { // Hard CLI gate. The Laravel console kernel already only runs // commands from CLI in practice, but a future HTTP-served // Artisan::call() (or a misconfigured kernel) must not be able // to mint a bearer through here. Bail before any work happens. if (! app()->runningInConsole()) { return Command::FAILURE; } ! defined('BASE_URL') && define('BASE_URL', ''); ! defined('CURRENT_URL') && define('CURRENT_URL', ''); $io = new SymfonyStyle($input, $output); $email = $input->getOption('email'); if ($email === null || ! filter_var($email, FILTER_VALIDATE_EMAIL)) { $io->error('A valid --email is required'); return Command::INVALID; } try { $usersRepo = app()->make(Users::class); $user = $usersRepo->getUserByEmail($email); if (! $user || empty($user['id'])) { $io->error("No user found with email: {$email}"); return Command::FAILURE; } $tokenRepo = app()->make(AccessTokenRepository::class); $result = $tokenRepo->createToken((int) $user['id'], (string) $input->getOption('name')); } catch (\Throwable $e) { $io->error($e->getMessage()); return Command::FAILURE; } if ($input->getOption('quiet-output')) { $output->write($result['token']); return Command::SUCCESS; } $io->success(sprintf( "Bearer token minted for user #%d (%s)\nToken id: %d\nToken: %s\n\nUse with: Authorization: Bearer %s", $user['id'], $email, $result['id'], $result['token'], $result['token'], )); return Command::SUCCESS; } }