Staff.php 992 B

123456789101112131415161718192021222324252627282930313233
  1. <?php
  2. namespace App\Http\Middleware;
  3. use Closure;
  4. class Staff
  5. {
  6. /**
  7. * Handle an incoming request.
  8. *
  9. * @param \Illuminate\Http\Request $request
  10. * @param \Closure $next
  11. * @return mixed
  12. */
  13. public function handle($request, Closure $next)
  14. {
  15. $authorization = $request->input('auth_data') ?? $request->header('authorization');
  16. if (!$authorization) abort(403, '未登录或登陆已过期');
  17. $authData = explode(':', base64_decode($authorization));
  18. if (!isset($authData[1]) || !isset($authData[0])) abort(403, '鉴权失败,请重新登入');
  19. $user = \App\Models\User::where('password', $authData[1])
  20. ->where('email', $authData[0])
  21. ->first();
  22. if (!$user) abort(403, '鉴权失败,请重新登入');
  23. if (!$user->is_staff) abort(403, '未登录或登陆已过期');
  24. $request->merge([
  25. 'user' => $user
  26. ]);
  27. return $next($request);
  28. }
  29. }