ManageAuthMiddleware.php 3.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123
  1. <?php
  2. /**
  3. * 后台认证中间件.
  4. *
  5. * @author nj
  6. * @date 2019-11-03 14:07:35
  7. */
  8. namespace Modules\ManageApi\Middlewares;
  9. use App\Constants\ErrorCodeConstant;
  10. use Closure;
  11. use App\Repositories\Utils\AccessControllerListsRepository;
  12. use App\Repositories\Utils\JwtRepository;
  13. use Modules\ManageApi\Services\ManageAuthService;
  14. use Cache;
  15. class ManageAuthMiddleware
  16. {
  17. protected $except = []; //URI里排除的操作
  18. /**
  19. * Handle an incoming request.
  20. *
  21. * @param \Illuminate\Http\Request $request
  22. * @param \Closure $next
  23. * @return mixed
  24. */
  25. public function handle($request, Closure $next)
  26. {
  27. if ($this->shouldPassThrough($request)) {
  28. return $next($request);
  29. }
  30. /**
  31. * @var ManageAuthService $authService
  32. */
  33. $authService = app(ManageAuthService::class);
  34. $token = $authService->getHeaderToken();
  35. if (empty($token)) {
  36. return json_fail(trans('common.err_failed_authorization'), 403);
  37. }
  38. /**
  39. * @var JwtRepository $jwtRepo
  40. */
  41. $jwtRepo = make(JwtRepository::class);
  42. $aud = 'manage-users';
  43. $validateResult = $jwtRepo->validateToken($token, $aud);
  44. if (!$validateResult['is_valid']) {
  45. return json_fail(trans('common.err_failed_authorization'), 403);
  46. } else {
  47. if ($validateResult['is_expired']) {
  48. return json_fail('认证过期', 401);
  49. }
  50. // 验证单点.
  51. $claim = $validateResult['token_obj']->claims();
  52. $tokenManagerUid = $claim->get('manager_uid');
  53. $tokenIp = $claim->get('ip');
  54. $clientIp = $jwtRepo->getClientIp();
  55. $cacheKey = $authService->getManagerCacheKey($tokenManagerUid);
  56. /**
  57. * @var Cache $cache
  58. */
  59. $cache = make('cache');
  60. $cacheToken = $cache->has($cacheKey) ? $cache->get($cacheKey) : '';
  61. if (empty($cacheToken) || $cacheToken !== $token) {
  62. return json_fail(trans('common.err_failed_authorization'), 403);
  63. }
  64. if (empty($tokenIp) || empty($clientIp) || $tokenIp !== $clientIp) {
  65. return json_fail(trans('common.err_failed_authorization'), 403);
  66. }
  67. }
  68. $managerInfo = $authService->getManagerInfo();
  69. $roleId = $managerInfo['role_id'];
  70. $managerUid = $managerInfo['manager_uid'];
  71. $authConfig = config('manage_acl');
  72. /**
  73. * @var AccessControllerListsRepository $aclRepo
  74. */
  75. $aclRepo = make(AccessControllerListsRepository::class);
  76. $aclRepo->init($authConfig, $roleId);
  77. $aclStatus = $aclRepo->check('Controller');
  78. if ($aclStatus !== true) {
  79. return json_fail('无权访问', ErrorCodeConstant::NO_PERMISSION);
  80. }
  81. return $next($request);
  82. }
  83. private function getExcepts()
  84. {
  85. $uriPrefix = env('MANAGE_API_URI_PREFIX', 'manage_api');
  86. $this->except = [
  87. $uriPrefix . '/pong',
  88. $uriPrefix .'/auth/login',
  89. $uriPrefix . '/auth/refresh/token',
  90. $uriPrefix . '/auth/logout',
  91. ];
  92. return $this->except;
  93. }
  94. /**
  95. * Determine if the request has a URI that should pass through CSRF verification.
  96. *
  97. * @param \Illuminate\Http\Request $request
  98. * @return bool
  99. */
  100. protected function shouldPassThrough($request)
  101. {
  102. foreach ($this->getExcepts() as $except) {
  103. if ($except !== '/') {
  104. $except = trim($except, '/');
  105. }
  106. if ($request->is($except)) {
  107. return true;
  108. }
  109. }
  110. return false;
  111. }
  112. }