WebLogin.php 3.0 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182
  1. <?php
  2. namespace App\Http\Middleware;
  3. use App\Helpers\Jwt;
  4. use App\Services\ConfigService;
  5. use App\Services\RedisService;
  6. use Closure;
  7. use Illuminate\Auth\Middleware\Authenticate as Middleware;
  8. class WebLogin extends Middleware
  9. {
  10. /**
  11. * 执行句柄
  12. * @param \Illuminate\Http\Request $request
  13. * @param Closure $next
  14. * @param mixed ...$guards
  15. * @return mixed
  16. * @throws \Illuminate\Auth\AuthenticationException
  17. * @since 2020/8/31
  18. * @author wesmiler
  19. */
  20. public function handle($request, Closure $next, ...$guards)
  21. {
  22. $action = app('request')->route()->getAction();
  23. $controller = class_basename($action['controller']);
  24. list($controller, $action) = explode('@', $controller);
  25. $noLoginActs = ['LoginController','UploadController','IndexController'];
  26. $token = $request->headers->get('Authorization');
  27. if (strpos($token, 'Bearer ') !== false) {
  28. $token = str_replace("Bearer ", null, $token);
  29. $token = trim($token);
  30. if($token){
  31. // JWT解密token
  32. $jwt = new Jwt('jwt_lgx_app');
  33. $userId = $jwt->verifyToken($token);
  34. }else{
  35. return response()->json(message(1035, false, [], 403))->setEncodingOptions(256);
  36. }
  37. } else {
  38. $userId = 0;
  39. }
  40. // 接口验证
  41. $url = $request->get('s');
  42. $url = empty($url)? $request->path() : $url;
  43. $params = $request->except('s');
  44. $sign = $request->header('sign');
  45. if(empty($sign)){
  46. $sign = isset($params['sign'])? $params['sign'] : '';
  47. }
  48. if($action != 'setAvatar'){
  49. $system = isset($params['system']) ? $params['system'] : '';
  50. $system = $system && !is_array($system)? json_decode($system,true) : $system;
  51. $ctime = isset($system['sys_time'])? $system['sys_time'] : 0;
  52. $uuid = isset($system['uuid'])? $system['uuid'] : 0;
  53. $url = '/'.ltrim($url,'/');
  54. $checkSign = getSign("{$url}&{$uuid}&{$ctime}");
  55. if ($ctime < time() - 30 && !in_array($controller, $noLoginActs)) {
  56. return response()->json(message(1012, false, null))->setEncodingOptions(256);
  57. }
  58. if ((empty($sign) || $sign != $checkSign) && !in_array($controller, $noLoginActs)) {
  59. return response()->json(message(1005, false, null))->setEncodingOptions(256);
  60. }
  61. }
  62. // 接口加密验证
  63. $userInfo = RedisService::get("auths:info:{$userId}");
  64. if (($userId<=0 || empty($userInfo))&& !in_array($controller, $noLoginActs)) {
  65. // 在这里可以定制你想要的返回格式, 亦或者是 JSON 编码格式
  66. return response()->json(message(1035, false, [], 403))->setEncodingOptions(256);
  67. }
  68. $request->headers->set('token_uid' , $userId);
  69. //如果已登录则执行正常的请求
  70. return $next($request);
  71. }
  72. }