ApiAuthMiddleware.php 3.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101
  1. <?php
  2. /**
  3. * 描述.
  4. *
  5. * @author nj <nj@gmail.com>
  6. * @date 2019-11-03 14:07:35
  7. */
  8. declare(strict_types=1);
  9. namespace Modules\Api\Middlewares;
  10. use App\Model\UserModel;
  11. use App\Repositories\Service\QueueService;
  12. use App\Repositories\Utils\JwtRepository;
  13. use Hyperf\HttpServer\Contract\RequestInterface;
  14. use Hyperf\HttpServer\Contract\ResponseInterface as HttpResponse;
  15. use Modules\Api\Services\AuthService;
  16. use Psr\Container\ContainerInterface;
  17. use Psr\Http\Message\ResponseInterface;
  18. use Psr\Http\Message\ServerRequestInterface;
  19. use Psr\Http\Server\MiddlewareInterface;
  20. use Psr\Http\Server\RequestHandlerInterface;
  21. use Psr\SimpleCache\CacheInterface;
  22. class ApiAuthMiddleware implements MiddlewareInterface
  23. {
  24. /**
  25. * 容器实例.
  26. *
  27. * @var ContainerInterface
  28. */
  29. protected $container = null;
  30. /**
  31. * 响应实例.
  32. *
  33. * @var HttpResponse
  34. */
  35. protected $response = null;
  36. /**
  37. * 请求实例.
  38. *
  39. * @var RequestInterface
  40. */
  41. protected $request = null;
  42. public function __construct(ContainerInterface $container, HttpResponse $response, RequestInterface $request)
  43. {
  44. $this->container = $container;
  45. $this->response = $response;
  46. $this->request = $request;
  47. }
  48. public function process(ServerRequestInterface $request, RequestHandlerInterface $handler): ResponseInterface
  49. {
  50. $authService = new AuthService();
  51. $enToken = $authService->getHeaderToken();
  52. $arrTokenInfo = $authService->decodeHeaderTokenInfo($enToken);
  53. $token = strval(data_get($arrTokenInfo, 'token', ''));
  54. if (empty($token)) {
  55. return json_fail('认证失败1', 403);
  56. }
  57. $jwtRepo = make(JwtRepository::class);
  58. $aud = 'app-users';
  59. $validateResult = $jwtRepo->validateToken($token, $aud);
  60. if (!$validateResult['is_valid']) {
  61. if ($validateResult['is_expired']) {
  62. return json_fail('认证过期', 401);
  63. }
  64. return json_fail('认证失败2', 403);
  65. } else {
  66. // 验证单点.
  67. $claims = $validateResult['token_obj']->claims();
  68. $deviceNo = $claims->get('device_no');
  69. $deviceType = $claims->get('device_type');
  70. $version = $claims->get('version');
  71. $code = $claims->get('user_id');
  72. $cacheKey = $authService->getUserDeviceCacheKey($deviceNo, $deviceType);
  73. $cache = make(CacheInterface::class);
  74. $cacheToken = $cache->has($cacheKey) ? $cache->get($cacheKey) : '';
  75. if (empty($cacheToken) || $cacheToken !== $token) {
  76. return json_fail('认证失败3', 403);
  77. }
  78. $hDeviceNo = data_get($arrTokenInfo, 'device_no', '');
  79. $hDeviceType = data_get($arrTokenInfo, 'device_type', '');
  80. $hVersion = data_get($arrTokenInfo, 'version', '');
  81. if ($hVersion != $version) {
  82. UserModel::query()->where('code', $code)
  83. ->update(['version' => $hVersion]);
  84. return json_fail(trans('common.err_failed_authorization'), 4999);
  85. }
  86. if ($hDeviceNo !== $deviceNo || $hDeviceType != $deviceType) {
  87. return json_fail('认证失败4', 403);
  88. }
  89. }
  90. return $handler->handle($request); // 洋葱管道正常执行下一个管道.
  91. }
  92. }