Auth routes
When NUKI_AUTH_USERS_ENABLED=true, routes/auth.php is loaded by the service provider and the bundled UI routes from routes/web.php are put behind the darvis-nuki guard. This page is the canonical list.
Common middleware
All routes registered under routes/auth.php use:
- The middleware group from
nuki.auth_users.routes.middleware(default['web']). - SetLocale, always appended.
URL prefix: nuki.auth_users.routes.prefix (default nuki). Route name prefix: nuki. (declared by the route group).
UI routes from routes/web.php use nuki.ui.middleware (default ['web']), then — when auth_users.enabled is on — AuthenticateNukiUser (Laravel’s auth middleware for the darvis-nuki guard), then AuthorizeUi and SetLocale. AuthorizeUi steps aside when auth_users.enabled is on; otherwise it asks the viewNuki gate, see Who may open the UI.
Guest routes
These routes run RedirectIfNukiUser, Laravel’s guest middleware for the darvis-nuki guard. A package user who is already signed in and opens one of these pages is redirected to auth_users.redirect_after_login. Before version 1.3.0 Laravel decided, and the user landed on the dashboard or home route of your application, or on /.
| Method | Path | Name | Component | Conditional on |
|---|---|---|---|---|
| GET | /login | nuki.auth.login | LoginPage | — |
| GET | /login/otp | nuki.auth.otp | LoginOtpPage | — |
| GET | /register | nuki.auth.register | RegisterPage | auth_users.register_enabled = true (default false) |
| GET | /password/forgot | nuki.auth.password.forgot | ForgotPasswordPage | auth_users.password_reset.enabled = true |
| GET | /password/reset/{token} | nuki.auth.password.reset | ResetPasswordPage | auth_users.password_reset.enabled = true |
| GET | /email/verify | nuki.auth.verify.notice | VerifyEmailNoticePage | auth_users.email_verification.enabled = true |
| GET | /email/verify/{id}/{hash} | nuki.auth.verify | NukiVerifyEmailController (extra signed middleware) | auth_users.email_verification.enabled = true |
The notice page reads session('nuki.pending_verification_user_id') (set on registration / a login attempt by an unverified account) and offers a throttled resend. The signed link marks the account verified and redirects to nuki.auth.login with a status flash. Unverified accounts cannot complete login: they are bounced back to the notice page.
Authenticated routes
| Method | Path | Name | Component |
|---|---|---|---|
| POST | /logout | nuki.auth.logout | NukiLogoutController |
| GET | /profile | nuki.profile | ProfilePage |
| GET | /sub-users | nuki.sub-users.index | SubUsersIndex |
| GET | /sub-users/{id} (numeric) | nuki.sub-users.show | SubUserShow |
The logout endpoint redirects to auth_users.redirect_after_logout (default /nuki/login).
UI routes (auto-wrapped)
These live in routes/web.php. When auth_users.enabled is true, they get AuthenticateNukiUser automatically. See Where a guest is sent for what that does to a visitor who is not signed in.
| Method | Path | Name | Component |
|---|---|---|---|
| GET | / | nuki.smartlocks.index | SmartlocksIndex |
| GET | /dashboard | nuki.dashboard | Dashboard |
| GET | /activity | nuki.activity.index | ActivityTimeline |
| GET | /smartlocks/{smartlockId} (numeric) | nuki.smartlocks.show | SmartlockShow |
| GET | /webhooks | nuki.webhooks.index | WebhooksIndex |
| GET | /oauth/connect | nuki.oauth.connect | OAuthConnect |
| GET | /accounts | nuki.accounts.index | AccountsIndex |
URL prefix: nuki.ui.prefix (default nuki). Route name prefix: nuki..
With auth_users.enabled, /webhooks, /oauth/connect and /accounts are for a main user only: a sub user gets 403 and does not see the links.
Where a guest is sent
A visitor who is not signed in and opens a page of the package is redirected to the package’s login page, /nuki/login (route nuki.auth.login). AuthenticateNukiUser does that: it is Laravel’s auth middleware for the darvis-nuki guard with its own redirect target. Your application’s redirectGuestsTo() is not touched and keeps working for your own pages.
Laravel remembers the page the guest asked for, and the package’s login ignores it: after signing in, the user always goes to auth_users.redirect_after_login.
Before version 1.3.0 the routes used the bare auth:darvis-nuki, which sends a guest to the route named login of your application, or fails with Route [login] not defined. when there is none. Earlier versions of this page showed a redirectGuestsTo() closure for bootstrap/app.php to work around that. From 1.3.0 on you do not need it; remove it, or leave it, it no longer sees the package pages.
Redirect targets
auth_users.redirect_after_login— default/nuki. Both the login without a code and the login after a code redirect here. It is a fixed path: a changedui.prefixdoes not change it.auth_users.redirect_after_logout— default/nuki/login. WherePOST /logoutsends the user.
Change these to integrate with your own host application’s chrome (e.g. send users back to your own dashboard).
Custom middleware
To wrap the auth routes in extra middleware (rate-limit, IP allow-list, something app-specific):
// config/nuki.php
'auth_users' => [
'routes' => [
'middleware' => ['web', 'throttle:5,1', \App\Http\Middleware\AllowOnlyOffice::class],
'prefix' => 'admin/nuki', // also moves the URLs
],
],
SetLocale is appended automatically; you don’t need to add it.
Bypassing the bundled UI entirely
You can use the darvis-nuki guard from your own routes:
use Darvis\Nuki\Http\Middleware\AuthenticateNukiUser;
Route::middleware(['web', AuthenticateNukiUser::class])->group(function () {
Route::get('/my/dashboard', MyDashboard::class);
});
AuthenticateNukiUser sends a guest to the package login. The bare auth:darvis-nuki works too, and sends a guest to your application’s login route.
Or switch the bundled pages off (NUKI_UI_ENABLED=false) and keep the auth routes. The guard and the login pages stay, and you write your own screens against the NukiUser model. Two things to set then:
auth_users.redirect_after_login, because/nukino longer exists.- Optionally
ui.layout, to a layout of your own./profile,/sub-usersand/sub-users/{id}render inui.layout. Since version 1.3.0 the package’s layout works without the UI routes: it leaves out the links and the account switcher, and the brand links toauth_users.redirect_after_login. Before 1.3.0 those three pages failed withRoute [nuki.dashboard] not defined.