TaoLer/app/middleware/Auth.php

72 lines
2.0 KiB
PHP
Raw Normal View History

2020-01-01 13:17:19 +08:00
<?php
declare(strict_types=1);
namespace app\middleware;
2020-02-12 17:20:07 +08:00
use taoser\think\Auth as UserAuth;
2020-01-01 13:17:19 +08:00
use think\facade\Session;
2021-12-15 15:46:04 +08:00
use think\facade\Cookie;
use think\facade\Db;
use think\facade\Config;
2020-01-01 13:17:19 +08:00
class Auth
{
/**
* 处理请求
*
* @param Request $request
* @param \Closure $next
* @return Response
*/
public function handle($request, \Closure $next)
{
2021-12-15 15:46:04 +08:00
//访问路径
2020-11-01 18:13:05 +08:00
$path = app('http')->getName().'/'.stristr($request->pathinfo(),".html",true);
2021-12-15 15:46:04 +08:00
//登陆前获取加密的Cookie
$cooAuth = Cookie::get('adminAuth');
if(!empty($cooAuth)){
$resArr = explode(':',$cooAuth);
$userId = end($resArr);
//检验用户
$user = Db::name('admin')->where('id',$userId)->find();
if(!empty($user)){
//验证cookie
$salt = Config::get('taoler.salt');
$auth = md5($user['username'].$salt).":".$userId;
if($auth==$cooAuth){
Session::set('admin_name',$user['username']);
Session::set('admin_id',$userId);
}
}
}
2020-11-01 18:13:05 +08:00
//没有登录及当前非登录页重定向登录页
if(!Session::has('admin_id') && $path !== 'admin/login/index' && !stristr($request->pathinfo(),"captcha.html") )
{
return redirect((string) url('admin/login/index'));
}
//登陆后无法访问登录页
if(Session::has('admin_id') && $path == 'admin/login/index'){
return redirect((string) url('admin/index/index'));
}
// 排除公共权限
$not_check = ['admin/','admin/login/index','admin/index/index','admin/index/home','admin/Admin/info','admin/Admin/repass','admin/Admin/logout','admin/Index/news','admin/Index/cunsult','admin/Index/replys','admin/Index/reply','admin/captcha','addons/socail/'];
2020-01-01 13:17:19 +08:00
2020-11-01 18:13:05 +08:00
if (!in_array($path, $not_check)) {
$auth = new UserAuth();
$admin_id = Session::get('admin_id'); //登录用户的id
2020-01-01 13:17:19 +08:00
2020-11-01 18:13:05 +08:00
if (!$auth->check($path, $admin_id) && $admin_id != 1) {
//return view('public/auth');
//return response("<script>alert('没有操作权限')</script>");
return json(['code'=>-1,'msg'=>'无权限']);
2020-01-01 13:17:19 +08:00
}
2020-11-01 18:13:05 +08:00
}
2021-12-15 15:46:04 +08:00
return $next($request);
2020-01-01 13:17:19 +08:00
}
}