---
tags: [companyuser, middleware]
module: CompanyUser
---

# Middleware

## Connections
[[_CompanyUser]] · [[[Model]User]] · [[[Model]RoleAndPermission]] · [[[Controller]IntegrationController]] · [[[Controller]UserController]] · [[[Cross]CrossModuleDependencies]]

## Source
`Modules/CompanyUser/Http/Middleware/`

## Authenticate
Enforces `auth:sanctum` (API) or `auth:web` (web) — all protected routes

## RedirectIfAuthenticated
Redirects already-logged-in users away from login/register pages

## CheckFirstUser
Allows the registration page only if no [[[Model]User]] records exist (first-run onboarding)

## IsStudentMiddleware
Blocks student-role accounts from accessing [[[Controller]UserController]] and [[[Controller]RolesController]] (for demo/trial accounts)

## TenantFeaturesAndRestrictions
Enforces subscription feature limits — checks `ActiveSubscription` ([[[Cross]CrossModuleDependencies#Tenant]]) on every request; applied globally, exempted for login route

## RestrictApplicationsIntegrationToUnlimitedPackage
Returns 403 if tenant plan does not include integration features; applied to all [[[Controller]IntegrationController]] routes
