# Flowchart — `auth`

> Produced by the Reversa **Archaeologist** (phase: excavation) · doc_level: `complete`
> Generated on 2026-09-16

**Confidence scale:** 🟢 CONFIRMED · 🟡 INFERRED · 🔴 GAP

## Request → authentication flow (live: Encore\Admin) 🟢

```mermaid
flowchart TD
    A[HTTP request] --> B{Route matched}
    B -->|"GET /"| C[Route::redirect to /pos - 301]
    B -->|"admin auth routes"| D["Admin::registerAuthRoutes<br/>(login / logout / password)"]
    B -->|"app routes"| E["middleware ['web','admin']"]
    E --> F{admin guard: authenticated?}
    F -->|no| G[redirect to admin login]
    F -->|yes| H{RBAC: permission for path?}
    H -->|denied| I[403 / forbidden]
    H -->|granted| J[Controller action]
    G --> D
```

## Dead framework-auth path (confirmed intentional) 🟢

```mermaid
flowchart TD
    A["Auth\\LoginController / RegisterController<br/>ForgotPassword / ResetPassword"] --> B["config/auth.php: guard 'web'<br/>provider 'users' -> App\\User::class"]
    B --> C{"App\\User exists?"}
    C -->|"NO (missing file)"| D["🟢 dead by design — never reachable:<br/>no Auth::routes() in web.php;<br/>admin-only app, no self-registration"]
```

**Notes:**
- Effective landing: `/` → 301 `/pos`; `HomeController::index` also `redirect()->to('pos')` (its Encore dashboard block is dead code). 🟢
- `RedirectIfAuthenticated` sends already-authenticated users to `/home`. 🟢
- The concrete permission check (node `H`) is implemented inside the vendored `Encore\Admin` package (`admin` middleware). Detail deferred to the Detective. 🟡
