shouldPassThrough($request)) { $xToken = $request->header('X-TOKEN', ''); $tokenSecret = env('INNERT_API_TOKEN_SECRET', Str::random(6)); if ($xToken !== $tokenSecret) { throw new InnerApiException('认证错误', 403); } } return $next($request); } /** * 获取排除项. * @return array */ public function getExcept() { return $this->except; } /** * Determine if the request has a URI that should pass through CSRF verification. * * @param \Illuminate\Http\Request $request * @return bool */ protected function shouldPassThrough($request) { foreach ($this->getExcept() as $except) { if ($except !== '/') { $except = trim($except, '/'); } if ($request->is($except)) { return true; } } return false; } }