Created
January 8, 2019 10:00
-
-
Save miyasinarafat/de44c578936c8a08376624f80bddf2c1 to your computer and use it in GitHub Desktop.
Middleware Permission to dynamically authorize users for spatie/laravel-permission. Using in lumen. Inspired from : https://gist.github.com/lamberttraccard/c0ab9c1ff7b52bd4eb9d8fa188c4470c
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| <?php | |
| namespace App\Http\Middleware; | |
| use App\Http\Controllers\V1\Auth\AuthController; | |
| use Closure; | |
| use Illuminate\Contracts\Auth\Factory as Auth; | |
| class Permission | |
| { | |
| /** | |
| * The authentication guard factory instance. | |
| * | |
| * @var \Illuminate\Contracts\Auth\Factory | |
| */ | |
| protected $auth, $routeName, $controller, $method; | |
| /** | |
| * Create a new middleware instance. | |
| * | |
| * @param \Illuminate\Contracts\Auth\Factory $auth | |
| * @return void | |
| */ | |
| public function __construct(Auth $auth) | |
| { | |
| $this->auth = $auth; | |
| } | |
| /** | |
| * List of controllers to handle. | |
| * | |
| * @var array | |
| */ | |
| protected $controllers = [ | |
| AuthController::class, | |
| ]; | |
| /** | |
| * List of actions with their mapping name to handle. | |
| * | |
| * @var array | |
| */ | |
| private $actions = [ | |
| 'index' => 'view', | |
| 'show' => 'view', | |
| 'edit' => 'edit', | |
| 'update' => 'edit', | |
| 'create' => 'add', | |
| 'store' => 'add', | |
| 'destroy' => 'delete', | |
| ]; | |
| /** | |
| * Handle an incoming request. | |
| * | |
| * @param \Illuminate\Http\Request $request | |
| * @param \Closure $next | |
| * @param null $guard | |
| * @return mixed | |
| */ | |
| public function handle($request, Closure $next, $guard = null) | |
| { | |
| // int request | |
| $explodeControllerAndMethod = explode('@', $request->route()[1]['uses']); | |
| $this->routeName = $request->route()[1]['as']; | |
| $this->controller = $this->getControllerName($explodeControllerAndMethod[0]); | |
| $this->method = $explodeControllerAndMethod[1]; | |
| // end int request | |
| if (!$this->shouldHandle()){ | |
| return $next($request); | |
| }; | |
| if ($this->auth->guard($guard)->guest()) { | |
| return response()->json(['errors' => [ | |
| 'status' => ['Unauthorized'] | |
| ]], 403); | |
| } | |
| if (app('auth')->user() !== null ? app('auth')->user()->can($this->getPermission()) : false) { | |
| return $next($request); | |
| } | |
| return response()->json(['errors' => [ | |
| 'status' => ['Unauthorized'] | |
| ]], 403); | |
| } | |
| /** | |
| * Should the request be handled. | |
| * | |
| * @return bool | |
| */ | |
| protected function shouldHandle(): bool | |
| { | |
| return $this->checkController() && $this->checkAction(); | |
| } | |
| /** | |
| * Check if the controller should be handle. | |
| * | |
| * @return bool | |
| */ | |
| protected function checkController(): bool | |
| { | |
| return collect($this->controllers)->contains(function ($item) { | |
| return $this->getControllerName($item) == $this->controller; | |
| }); | |
| } | |
| /** | |
| * check if the action should be handle. | |
| * | |
| * @return bool | |
| */ | |
| protected function checkAction(): bool | |
| { | |
| return collect($this->actions)->has($this->method); | |
| } | |
| /** | |
| * Get the permission name for the given request. | |
| * | |
| * @return null|string | |
| */ | |
| protected function getPermission() | |
| { | |
| $routeName = explode('.', $this->routeName); | |
| $action = $this->actions[$this->method]; | |
| return $action ? $action.'_'.$routeName[0] : null; | |
| } | |
| /** | |
| * Get controller name from namespace string | |
| * | |
| * @param $string | |
| * @return mixed | |
| */ | |
| protected function getControllerName($string) | |
| { | |
| $controllerArray = explode('\\', $string); | |
| return end($controllerArray); | |
| } | |
| } |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment