| 1234567891011121314151617181920212223242526272829 |
- <?php
- namespace App\Http\Middleware;
- use App\Services\AuthService;
- use Closure;
- class Staff
- {
- /**
- * Handle an incoming request.
- *
- * @param \Illuminate\Http\Request $request
- * @param \Closure $next
- * @return mixed
- */
- public function handle($request, Closure $next)
- {
- $authorization = $request->input('auth_data') ?? $request->header('authorization');
- if (!$authorization) abort(403, '未登录或登陆已过期');
- $user = AuthService::decryptAuthData($authorization);
- if (!$user || !$user['is_staff']) abort(403, '未登录或登陆已过期');
- $request->merge([
- 'user' => $user
- ]);
- return $next($request);
- }
- }
|