AgentAuthMiddleware.php 3.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110
  1. <?php
  2. /**
  3. * 后台认证中间件.
  4. *
  5. * @author nj
  6. * @date 2019-11-03 14:07:35
  7. */
  8. namespace Modules\AgentApi\Middlewares;
  9. use App\Constants\ErrorCodeConstant;
  10. use Closure;
  11. use App\Repositories\Utils\AccessControllerListsRepository;
  12. use App\Repositories\Utils\JwtRepository;
  13. use Modules\AgentApi\Services\AgentAuthService;
  14. use Cache;
  15. class AgentAuthMiddleware
  16. {
  17. protected $except = []; //URI里排除的操作
  18. /**
  19. * Handle an incoming request.
  20. *
  21. * @param \Illuminate\Http\Request $request
  22. * @param \Closure $next
  23. * @return mixed
  24. */
  25. public function handle($request, Closure $next)
  26. {
  27. if ($this->shouldPassThrough($request)) {
  28. return $next($request);
  29. }
  30. /**
  31. * @var AgentAuthService $authService
  32. */
  33. $authService = app(AgentAuthService::class);
  34. $token = $authService->getHeaderToken();
  35. if (empty($token)) {
  36. return json_fail(trans('common.err_failed_authorization'), 403);
  37. }
  38. /**
  39. * @var JwtRepository $jwtRepo
  40. */
  41. $jwtRepo = make(JwtRepository::class);
  42. $aud = 'agent-users';
  43. $validateResult = $jwtRepo->validateToken($token, $aud);
  44. if (!$validateResult['is_valid']) {
  45. return json_fail(trans('common.err_failed_authorization'), 403);
  46. } else {
  47. if ($validateResult['is_expired']) {
  48. return json_fail('认证过期', 401);
  49. }
  50. // 验证单点.
  51. $claim = $validateResult['token_obj']->claims();
  52. $tokenAgentUid = $claim->get('agent_uid');
  53. $tokenIp = $claim->get('ip');
  54. $clientIp = $jwtRepo->getClientIp();
  55. $cacheKey = $authService->getAgentCacheKey($tokenAgentUid);
  56. /**
  57. * @var Cache $cache
  58. */
  59. $cache = make('cache');
  60. $cacheToken = $cache->has($cacheKey) ? $cache->get($cacheKey) : '';
  61. if (empty($cacheToken) || $cacheToken !== $token) {
  62. return json_fail(trans('common.err_failed_authorization'), 403);
  63. }
  64. if (empty($tokenIp) || empty($clientIp) || $tokenIp !== $clientIp) {
  65. return json_fail(trans('common.err_failed_authorization'), 403);
  66. }
  67. }
  68. return $next($request);
  69. }
  70. private function getExcepts()
  71. {
  72. $uriPrefix = env('AGENT_API_URI_PREFIX', 'agent_api');
  73. $this->except = [
  74. $uriPrefix . '/ping',
  75. $uriPrefix .'/auth/login',
  76. $uriPrefix . '/auth/refresh/token',
  77. $uriPrefix . '/auth/logout',
  78. $uriPrefix . '/chunqiu/captcha',
  79. ];
  80. return $this->except;
  81. }
  82. /**
  83. * Determine if the request has a URI that should pass through CSRF verification.
  84. *
  85. * @param \Illuminate\Http\Request $request
  86. * @return bool
  87. */
  88. protected function shouldPassThrough($request)
  89. {
  90. foreach ($this->getExcepts() as $except) {
  91. if ($except !== '/') {
  92. $except = trim($except, '/');
  93. }
  94. if ($request->is($except)) {
  95. return true;
  96. }
  97. }
  98. return false;
  99. }
  100. }