shouldPassThrough($request)) { return $next($request); } /** * @var AgentAuthService $authService */ $authService = app(AgentAuthService::class); $token = $authService->getHeaderToken(); if (empty($token)) { return json_fail(trans('common.err_failed_authorization'), 403); } /** * @var JwtRepository $jwtRepo */ $jwtRepo = make(JwtRepository::class); $aud = 'agent-users'; $validateResult = $jwtRepo->validateToken($token, $aud); if (!$validateResult['is_valid']) { return json_fail(trans('common.err_failed_authorization'), 403); } else { if ($validateResult['is_expired']) { return json_fail('认证过期', 401); } // 验证单点. $claim = $validateResult['token_obj']->claims(); $tokenAgentUid = $claim->get('agent_uid'); $tokenIp = $claim->get('ip'); $clientIp = $jwtRepo->getClientIp(); $cacheKey = $authService->getAgentCacheKey($tokenAgentUid); /** * @var Cache $cache */ $cache = make('cache'); $cacheToken = $cache->has($cacheKey) ? $cache->get($cacheKey) : ''; if (empty($cacheToken) || $cacheToken !== $token) { return json_fail(trans('common.err_failed_authorization'), 403); } if (empty($tokenIp) || empty($clientIp) || $tokenIp !== $clientIp) { return json_fail(trans('common.err_failed_authorization'), 403); } } return $next($request); } private function getExcepts() { $uriPrefix = env('AGENT_API_URI_PREFIX', 'agent_api'); $this->except = [ $uriPrefix . '/ping', $uriPrefix .'/auth/login', $uriPrefix . '/auth/refresh/token', $uriPrefix . '/auth/logout', $uriPrefix . '/chunqiu/captcha', ]; return $this->except; } /** * Determine if the request has a URI that should pass through CSRF verification. * * @param \Illuminate\Http\Request $request * @return bool */ protected function shouldPassThrough($request) { foreach ($this->getExcepts() as $except) { if ($except !== '/') { $except = trim($except, '/'); } if ($request->is($except)) { return true; } } return false; } }