Login.php 2.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172
  1. <?php
  2. namespace App\Http\Middleware\Manager;
  3. use App\Facades\Servers\Encrypts\AccessToken;
  4. use Closure;
  5. use Illuminate\Http\Request;
  6. class Login
  7. {
  8. // 无需验证的路径
  9. protected $except = [
  10. 'manager/login/index',
  11. 'manager/login/mobile',
  12. 'manager/citys/list'
  13. ];
  14. //默认配置
  15. protected $_config = [
  16. 'auth_on' => true, // 认证开关
  17. 'auth_type' => 1, // 认证方式,1为实时认证;2为登录认证。
  18. 'auth_group' => 'auth_group', // 用户组数据表名
  19. 'auth_group_access' => 'auth_group_access', // 用户-用户组关系表
  20. 'auth_rule' => 'auth_rule' // 权限规则表
  21. ];
  22. /**
  23. * $prefix表前缀
  24. */
  25. public function __construct()
  26. {
  27. // 判断配置
  28. if (config('AUTH_CONFIG')) {
  29. //可设置配置项 AUTH_CONFIG, 此配置项为数组。
  30. $this->_config = array_merge($this->_config, config('AUTH_CONFIG'));
  31. }
  32. }
  33. /**
  34. * Handle an incoming request.
  35. *
  36. * @param \Illuminate\Http\Request $request
  37. * @param \Closure $next
  38. * @return mixed
  39. */
  40. public function handle(Request $request, Closure $next)
  41. {
  42. // 当前路径
  43. $path = ltrim($request->getPathInfo(), '/');
  44. // 判断是否需要验证登录
  45. if (!in_array($path, $this->except)) {
  46. // 获取登录结果
  47. $token = (string) $request->input('access_token_manager', '');
  48. // 解码
  49. $userInfo = AccessToken::decode($token);
  50. // 判断登录时效
  51. if (isset($userInfo['error'])) return json_send(['code' => 'no_login', 'msg' => '请您登录', 'data' => $userInfo['error']]);
  52. if ($userInfo['type'] != 'manager') return json_send(['code' => 'no_login', 'msg' => '请您登录', 'data' => '登录失效']);
  53. if ($userInfo['expire'] < time()) return json_send(['code' => 'no_login', 'msg' => '登录失效,请您重新登录', 'data' => '登录失效']);
  54. // 获取就得令牌
  55. // $oldToken = (new AdminUser())->getLogin($userInfo['uid'],'manager');
  56. // 比对令牌
  57. // if( $oldToken != md5($token) ) return json_send(['code'=>'no_login','msg'=>'登录失效,请重新登录']);
  58. // 是否是超管
  59. $userInfo['is_super'] = is_super($userInfo['uid'], 'manager') ? 1 : 0;
  60. // 追加入
  61. $request['access_token'] = $userInfo;
  62. }
  63. // 返回下一个闭包
  64. return $next($request);
  65. }
  66. }