ManageAuthMiddleware.php 3.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104
  1. <?php
  2. /**
  3. * 后台认证中间件.
  4. *
  5. * @author nj <nj@gmail.com>
  6. * @date 2019-11-03 14:07:35
  7. */
  8. declare(strict_types=1);
  9. namespace Modules\Manage\Middlewares;
  10. use App\Constants\ErrorCode;
  11. use App\Repositories\Utils\AccessControllerListsRepository;
  12. use App\Repositories\Utils\JwtRepository;
  13. use Hyperf\HttpServer\Contract\RequestInterface;
  14. use Hyperf\HttpServer\Contract\ResponseInterface as HttpResponse;
  15. use Lcobucci\JWT\UnencryptedToken;
  16. use Modules\Manage\Services\AuthService;
  17. use Psr\Container\ContainerInterface;
  18. use Psr\Http\Message\ResponseInterface;
  19. use Psr\Http\Message\ServerRequestInterface;
  20. use Psr\Http\Server\MiddlewareInterface;
  21. use Psr\Http\Server\RequestHandlerInterface;
  22. use Psr\SimpleCache\CacheInterface;
  23. class ManageAuthMiddleware implements MiddlewareInterface
  24. {
  25. /**
  26. * 容器实例.
  27. *
  28. * @var ContainerInterface
  29. */
  30. protected $container = null;
  31. /**
  32. * 响应实例.
  33. *
  34. * @var HttpResponse
  35. */
  36. protected $response = null;
  37. /**
  38. * 请求实例.
  39. *
  40. * @var RequestInterface
  41. */
  42. protected $request = null;
  43. public function __construct(ContainerInterface $container, HttpResponse $response, RequestInterface $request)
  44. {
  45. $this->container = $container;
  46. $this->response = $response;
  47. $this->request = $request;
  48. }
  49. public function process(ServerRequestInterface $request, RequestHandlerInterface $handler): ResponseInterface
  50. {
  51. $authService = new AuthService;
  52. $token = $authService->getHeaderToken();
  53. if (empty($token)) {
  54. return json_fail(trans('common.err_failed_authorization'), 403);
  55. }
  56. $jwtRepo = make(JwtRepository::class);
  57. $aud = 'manage-users';
  58. $validateResult = $jwtRepo->validateToken($token, $aud);
  59. if (!$validateResult['is_valid']) {
  60. if ($validateResult['is_expired']) {
  61. return json_fail('认证过期', 401);
  62. }
  63. return json_fail(trans('common.err_failed_authorization'), 403);
  64. } else {
  65. /**
  66. * @var UnencryptedToken $tokenObj
  67. */
  68. $tokenObj = $validateResult['token_obj'];
  69. // 验证单点.
  70. $tokenManagerId = $tokenObj->claims()->get('manager_id');
  71. $tokenIp = $tokenObj->claims()->get('ip');
  72. $clientIp = $jwtRepo->getClientIp();
  73. $cacheKey = $authService->getManagerCacheKey($tokenManagerId);
  74. $cache = make(CacheInterface::class);
  75. $cacheToken = $cache->has($cacheKey) ? $cache->get($cacheKey) : '';
  76. if (empty($cacheToken) || $cacheToken !== $token) {
  77. return json_fail(trans('common.err_failed_authorization'), 403);
  78. }
  79. if (empty($tokenIp) || empty($clientIp) || $tokenIp !== $clientIp) {
  80. return json_fail(trans('common.err_failed_authorization'), 403);
  81. }
  82. }
  83. $managerInfo = $authService->getManagerInfo();
  84. $roleId = $managerInfo['role_id'];
  85. $managerId = $managerInfo['manager_id'];
  86. $authConfig = config('manage_acl');
  87. $aclRepo = make(AccessControllerListsRepository::class);
  88. $aclRepo->init($authConfig, $roleId);
  89. $aclStatus = $aclRepo->check('Controller');
  90. if ($aclStatus !== true) {
  91. return json_fail('无权访问', ErrorCode::NO_PERMISSION);
  92. }
  93. return $handler->handle($request); // 洋葱管道正常执行下一个管道.
  94. }
  95. }