AdminAuthMiddleware.php 2.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172
  1. <?php
  2. namespace App\Http\Middleware;
  3. use App\Exceptions\MemberAuthException;
  4. use App\Models\User;
  5. use App\Servers\System\PermissionServer;
  6. use Closure;
  7. use Illuminate\Support\Facades\Auth;
  8. class AdminAuthMiddleware
  9. {
  10. private $noAuth = [
  11. 'adminApi.auth.login',
  12. 'adminApi.auth.retrieve',//忘记密码
  13. 'adminApi.common.send',
  14. 'adminApi.auth.retrieve',
  15. 'adminApi.notify.esignNotify'
  16. ];
  17. /**
  18. * Handle an incoming request.
  19. *
  20. * @param \Illuminate\Http\Request $request
  21. * @param \Closure $next
  22. * @return mixed
  23. */
  24. public function handle($request, Closure $next)
  25. {
  26. $clientRoute = request()->route()->getName();//获取当前路由
  27. if (in_array($clientRoute, $this->noAuth)) {//不需要验证的路由
  28. return $next($request);
  29. }
  30. $apiToken=$request->input('api_token','');
  31. if(empty($apiToken)){
  32. $apiToken=$request->header('Authorization');
  33. }
  34. $user=User::where('api_token',$apiToken)->where('is_del',0)->select(['id','name','status','roles_id'])->first();
  35. if(empty($user)){
  36. return response()->json([
  37. 'msg' => '请先登录',
  38. 'code' => 401,
  39. 'data' => []
  40. ]);
  41. }
  42. if(empty($user->{'status'})){
  43. return response()->json([
  44. 'msg' => '当前账户已锁定',
  45. 'code' => 401,
  46. 'data' => []
  47. ]);
  48. }
  49. Auth::loginUsingId($user->{'id'});
  50. //进行路由验证
  51. // $ret = PermissionServer::creatServer()->verifyPermission($user->{'id'}, $clientRoute,0);
  52. // if (empty($ret) ) {
  53. // if($request->ajax()){
  54. // return response()->json([
  55. // 'msg' => '暂无权限',
  56. // 'code' => 0,
  57. // 'data' => []
  58. // ]);
  59. // }else{
  60. // return $next($request);
  61. // }
  62. //
  63. // }
  64. return $next($request);
  65. }
  66. }