1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980 |
- <?php
- namespace App\Http\Middleware;
- use App\Helpers\Jwt;
- use App\Services\ConfigService;
- use Closure;
- use Illuminate\Auth\Middleware\Authenticate as Middleware;
- class WebLogin extends Middleware
- {
- /**
- * 执行句柄
- * @param \Illuminate\Http\Request $request
- * @param Closure $next
- * @param mixed ...$guards
- * @return mixed
- * @throws \Illuminate\Auth\AuthenticationException
- * @since 2020/8/31
- * @author wesmiler
- */
- public function handle($request, Closure $next, ...$guards)
- {
- $action = app('request')->route()->getAction();
- $controller = class_basename($action['controller']);
- list($controller, $action) = explode('@', $controller);
- $noLoginActs = ['LoginController','GoodsController','IndexController','UploadController'];
- $token = $request->headers->get('Authorization');
- if (strpos($token, 'Bearer ') !== false) {
- $token = str_replace("Bearer ", null, $token);
- $token = trim($token);
- if($token){
- // JWT解密token
- $jwt = new Jwt('jwt_yd_app');
- $userId = $jwt->verifyToken($token);
- }else{
- return response()->json(message(1035, false, [], 403))->setEncodingOptions(256);
- }
- } else {
- $userId = 0;
- }
- // 接口验证
- $url = $request->get('s');
- $url = empty($url)? $request->path() : $url;
- $params = $request->except('s');
- $sign = $request->header('sign');
- if(empty($sign)){
- $sign = isset($params['sign'])? $params['sign'] : '';
- }
- $system = isset($params['system']) ? $params['system'] : '';
- $system = $system && !is_array($system)? json_decode($system,true) : $system;
- $ctime = isset($system['sys_time'])? $system['sys_time'] : 0;
- $uuid = isset($system['uuid'])? $system['uuid'] : 0;
- $url = '/'.ltrim($url,'/');
- $checkSign = getSign("{$url}&{$uuid}&{$ctime}");
- if ($ctime < time() - 30) {
- return response()->json(message(1012, false, null))->setEncodingOptions(256);
- }
- var_dump("{$url}&{$uuid}&{$ctime}");
- var_dump($sign,$checkSign);
- if ((empty($sign) || $sign != $checkSign) && !in_array($controller, $noLoginActs)) {
- return response()->json(message(1036, false, null))->setEncodingOptions(256);
- }
- // 接口加密验证
- if ($userId<=0 && !in_array($controller, $noLoginActs)) {
- // 在这里可以定制你想要的返回格式, 亦或者是 JSON 编码格式
- return response()->json(message(1035, false, [], 403))->setEncodingOptions(256);
- }
- $request->headers->set('token_uid' , $userId);
- //如果已登录则执行正常的请求
- return $next($request);
- }
- }
|