| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172 |
- <?php
- namespace App\Http\Middleware;
- use App\Exceptions\MemberAuthException;
- use App\Models\User;
- use App\Servers\System\PermissionServer;
- use Closure;
- use Illuminate\Support\Facades\Auth;
- class AdminAuthMiddleware
- {
- private $noAuth = [
- 'adminApi.auth.login',
- 'adminApi.auth.retrieve',//忘记密码
- 'adminApi.common.send',
- 'adminApi.auth.retrieve',
- 'adminApi.notify.esignNotify'
- ];
- /**
- * Handle an incoming request.
- *
- * @param \Illuminate\Http\Request $request
- * @param \Closure $next
- * @return mixed
- */
- public function handle($request, Closure $next)
- {
- $clientRoute = request()->route()->getName();//获取当前路由
- if (in_array($clientRoute, $this->noAuth)) {//不需要验证的路由
- return $next($request);
- }
- $apiToken=$request->input('api_token','');
- if(empty($apiToken)){
- $apiToken=$request->header('Authorization');
- }
- $user=User::where('api_token',$apiToken)->where('is_del',0)->select(['id','name','status','roles_id'])->first();
- if(empty($user)){
- return response()->json([
- 'msg' => '请先登录',
- 'code' => 401,
- 'data' => []
- ]);
- }
- if(empty($user->{'status'})){
- return response()->json([
- 'msg' => '当前账户已锁定',
- 'code' => 401,
- 'data' => []
- ]);
- }
- Auth::loginUsingId($user->{'id'});
- //进行路由验证
- // $ret = PermissionServer::creatServer()->verifyPermission($user->{'id'}, $clientRoute,0);
- // if (empty($ret) ) {
- // if($request->ajax()){
- // return response()->json([
- // 'msg' => '暂无权限',
- // 'code' => 0,
- // 'data' => []
- // ]);
- // }else{
- // return $next($request);
- // }
- //
- // }
- return $next($request);
- }
- }
|