| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123 |
- <?php
- /**
- * 后台认证中间件.
- *
- * @author nj
- * @date 2019-11-03 14:07:35
- */
- namespace Modules\ManageApi\Middlewares;
- use App\Constants\ErrorCodeConstant;
- use Closure;
- use App\Repositories\Utils\AccessControllerListsRepository;
- use App\Repositories\Utils\JwtRepository;
- use Modules\ManageApi\Services\ManageAuthService;
- use Cache;
- class ManageAuthMiddleware
- {
- protected $except = []; //URI里排除的操作
- /**
- * Handle an incoming request.
- *
- * @param \Illuminate\Http\Request $request
- * @param \Closure $next
- * @return mixed
- */
- public function handle($request, Closure $next)
- {
- if ($this->shouldPassThrough($request)) {
- return $next($request);
- }
- /**
- * @var ManageAuthService $authService
- */
- $authService = app(ManageAuthService::class);
- $token = $authService->getHeaderToken();
- if (empty($token)) {
- return json_fail(trans('common.err_failed_authorization'), 403);
- }
- /**
- * @var JwtRepository $jwtRepo
- */
- $jwtRepo = make(JwtRepository::class);
- $aud = 'manage-users';
- $validateResult = $jwtRepo->validateToken($token, $aud);
- if (!$validateResult['is_valid']) {
- return json_fail(trans('common.err_failed_authorization'), 403);
- } else {
- if ($validateResult['is_expired']) {
- return json_fail('认证过期', 401);
- }
- // 验证单点.
- $claim = $validateResult['token_obj']->claims();
- $tokenManagerUid = $claim->get('manager_uid');
- $tokenIp = $claim->get('ip');
- $clientIp = $jwtRepo->getClientIp();
- $cacheKey = $authService->getManagerCacheKey($tokenManagerUid);
- /**
- * @var Cache $cache
- */
- $cache = make('cache');
- $cacheToken = $cache->has($cacheKey) ? $cache->get($cacheKey) : '';
- if (empty($cacheToken) || $cacheToken !== $token) {
- return json_fail(trans('common.err_failed_authorization'), 403);
- }
- if (empty($tokenIp) || empty($clientIp) || $tokenIp !== $clientIp) {
- return json_fail(trans('common.err_failed_authorization'), 403);
- }
- }
- $managerInfo = $authService->getManagerInfo();
- $roleId = $managerInfo['role_id'];
- $managerUid = $managerInfo['manager_uid'];
- $authConfig = config('manage_acl');
- /**
- * @var AccessControllerListsRepository $aclRepo
- */
- $aclRepo = make(AccessControllerListsRepository::class);
- $aclRepo->init($authConfig, $roleId);
- $aclStatus = $aclRepo->check('Controller');
- if ($aclStatus !== true) {
- return json_fail('无权访问', ErrorCodeConstant::NO_PERMISSION);
- }
- return $next($request);
- }
- private function getExcepts()
- {
- $uriPrefix = env('MANAGE_API_URI_PREFIX', 'manage_api');
- $this->except = [
- $uriPrefix . '/pong',
- $uriPrefix .'/auth/login',
- $uriPrefix . '/auth/refresh/token',
- $uriPrefix . '/auth/logout',
- ];
- return $this->except;
- }
- /**
- * Determine if the request has a URI that should pass through CSRF verification.
- *
- * @param \Illuminate\Http\Request $request
- * @return bool
- */
- protected function shouldPassThrough($request)
- {
- foreach ($this->getExcepts() as $except) {
- if ($except !== '/') {
- $except = trim($except, '/');
- }
- if ($request->is($except)) {
- return true;
- }
- }
- return false;
- }
- }
|