AdminApiAuthMiddleware.php 1.9 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071
  1. <?php
  2. namespace App\Http\Middleware;
  3. use App\Models\UserModels\User;
  4. use App\Servers\Common\RedisDataServer;
  5. use Closure;
  6. class AdminApiAuthMiddleware
  7. {
  8. private $noAuth = [
  9. 'adminApi.login',
  10. 'adminApi.logout',
  11. ];
  12. /**
  13. * Handle an incoming request.
  14. *
  15. * @param \Illuminate\Http\Request $request
  16. * @param \Closure $next
  17. * @return mixed
  18. */
  19. public function handle($request, Closure $next)
  20. {
  21. $clientRoute = request()->route()->getName();//获取当前路由
  22. if (in_array($clientRoute, $this->noAuth)) {//不需要验证的路由
  23. return $next($request);
  24. }
  25. //获取token
  26. $api_token = $request->input('api_token');
  27. if(empty($api_token)) $api_token = $request->header('ApiToken');
  28. if(empty($api_token)){
  29. return response()->json([
  30. 'msg' => '缺少认证信息',
  31. 'code' => 401,
  32. 'data' => []
  33. ]);
  34. }
  35. //获取当前用户
  36. $user = RedisDataServer::creatServer()->getData( 'gw_adminLogin_' . $api_token, 'json');
  37. if(!$user){
  38. //数据库查找当前用户
  39. $user = User::where('api_token', $api_token)->where('is_del', 0)->first();
  40. if($user){
  41. //用户信息缓存
  42. RedisDataServer::creatServer()->setData('gw_adminLogin_' . $api_token, $user, 'json', 300);
  43. }else{
  44. return response()->json([
  45. 'msg' => '身份验证失败',
  46. 'code' => 401,
  47. 'data' => []
  48. ]);
  49. }
  50. }
  51. //状态验证
  52. if($user['status'] == 2){
  53. return response()->json([
  54. 'msg' => '账号已关闭',
  55. 'code' => 402,
  56. 'data' => []
  57. ]);
  58. }
  59. $request->admin_user = $user;
  60. return $next($request);
  61. }
  62. }