whereHas('paciente', fn ($q) => $q->whereNotNull('senha')) ->first(); if (is_null($cidadao) || !Hash::check($dados['senha'], $cidadao->paciente->senha)) { throw new \InvalidArgumentException('CPF e/ou senha incorreto(s).', Response::HTTP_UNAUTHORIZED); } $usuario = $cidadao->paciente; $token = auth('mobile')->setTTL(15)->login($usuario); $refreshToken = auth('mobile') ->claims(['type' => 'refresh']) ->setTTL(10080) ->tokenById($usuario->id); return [ 'expiration' => time() + 15 * 60, 'token' => $token, 'refresh_token' => $refreshToken, 'usuario' => [ 'cpf' => $dados['cpf'], 'nome' => $cidadao->nome, 'paciente_id' => $cidadao->paciente->id, ], ]; } public function refresh() { $payload = auth('mobile')->payload(); if ($payload->get('type') !== 'refresh') { return response()->json(['error' => 'Token inválido'], 401); } $user = auth('mobile')->user(); auth('mobile')->invalidate(); $accessToken = auth('mobile') ->claims(['type' => 'access']) ->setTTL(15) ->tokenById($user->id); $refreshToken = auth('mobile') ->claims(['type' => 'refresh']) ->setTTL(10080) ->tokenById($user->id); return [ 'token' => $accessToken, 'refresh_token' => $refreshToken, 'expiration' => time() + 15 * 60, ]; } }