# App Companies

## What it does

Super Admins manage the private company servers used for mobile email/password
sign-in. The initial directory is empty. Adding, editing, enabling, disabling or
removing a company takes effect on the next login without an App update.

## How it works

Setting > App Companies opens `/manage/settings/company-accounts?suite=other`.
Both GET and PUT require the existing auth/admin/super-admin middleware. The
FormRequest normalizes HTTPS origins and rejects duplicates, unsafe addresses
and extra fields. SettingRepository atomically saves names, origins and enabled
flags as JSON in `settings.agent_app.company_directory` (a setting key, not a
column). There is no schema change or seed directory.

CompanyDirectory reads that setting on each login. CompanyLoginBroker contacts
only enabled entries and returns only successfully authenticated identities.
An empty/all-disabled directory returns 503 with no upstream requests. There is
no public directory endpoint. Disabling a company stops new broker logins;
existing tokens remain governed by the owning server.

## Related files

- `app/Services/AgentApp/CompanyDirectory.php`
- `app/Services/AgentApp/CompanyLoginBroker.php`
- `app/Http/Controllers/Manage/Settings/CompanyAccountsController.php`
- `app/Http/Requests/Manage/Settings/CompanyAccounts/UpdateRequest.php`
- `src/Setting/Setting.php`, `src/Setting/Repositories/SettingRepository.php`
- `routes/web.php`, `routes/company-entry.php`
- `resources/js/Pages/Manage/Settings/CompanyAccounts.vue`
- `resources/js/Components/SettingTabs.vue`
- `tests/Feature/AgentApi/CompanyDirectorySettingsTest.php`
- `tests/Feature/AgentApi/CompanyLoginTest.php`
- `docs/company-accounts-deployment.md`
