Skip to content

Instantly share code, notes, and snippets.

@miyasinarafat
Created January 8, 2019 10:00
Show Gist options
  • Select an option

  • Save miyasinarafat/de44c578936c8a08376624f80bddf2c1 to your computer and use it in GitHub Desktop.

Select an option

Save miyasinarafat/de44c578936c8a08376624f80bddf2c1 to your computer and use it in GitHub Desktop.
Middleware Permission to dynamically authorize users for spatie/laravel-permission. Using in lumen. Inspired from : https://gist.github.com/lamberttraccard/c0ab9c1ff7b52bd4eb9d8fa188c4470c
<?php
namespace App\Http\Middleware;
use App\Http\Controllers\V1\Auth\AuthController;
use Closure;
use Illuminate\Contracts\Auth\Factory as Auth;
class Permission
{
/**
* The authentication guard factory instance.
*
* @var \Illuminate\Contracts\Auth\Factory
*/
protected $auth, $routeName, $controller, $method;
/**
* Create a new middleware instance.
*
* @param \Illuminate\Contracts\Auth\Factory $auth
* @return void
*/
public function __construct(Auth $auth)
{
$this->auth = $auth;
}
/**
* List of controllers to handle.
*
* @var array
*/
protected $controllers = [
AuthController::class,
];
/**
* List of actions with their mapping name to handle.
*
* @var array
*/
private $actions = [
'index' => 'view',
'show' => 'view',
'edit' => 'edit',
'update' => 'edit',
'create' => 'add',
'store' => 'add',
'destroy' => 'delete',
];
/**
* Handle an incoming request.
*
* @param \Illuminate\Http\Request $request
* @param \Closure $next
* @param null $guard
* @return mixed
*/
public function handle($request, Closure $next, $guard = null)
{
// int request
$explodeControllerAndMethod = explode('@', $request->route()[1]['uses']);
$this->routeName = $request->route()[1]['as'];
$this->controller = $this->getControllerName($explodeControllerAndMethod[0]);
$this->method = $explodeControllerAndMethod[1];
// end int request
if (!$this->shouldHandle()){
return $next($request);
};
if ($this->auth->guard($guard)->guest()) {
return response()->json(['errors' => [
'status' => ['Unauthorized']
]], 403);
}
if (app('auth')->user() !== null ? app('auth')->user()->can($this->getPermission()) : false) {
return $next($request);
}
return response()->json(['errors' => [
'status' => ['Unauthorized']
]], 403);
}
/**
* Should the request be handled.
*
* @return bool
*/
protected function shouldHandle(): bool
{
return $this->checkController() && $this->checkAction();
}
/**
* Check if the controller should be handle.
*
* @return bool
*/
protected function checkController(): bool
{
return collect($this->controllers)->contains(function ($item) {
return $this->getControllerName($item) == $this->controller;
});
}
/**
* check if the action should be handle.
*
* @return bool
*/
protected function checkAction(): bool
{
return collect($this->actions)->has($this->method);
}
/**
* Get the permission name for the given request.
*
* @return null|string
*/
protected function getPermission()
{
$routeName = explode('.', $this->routeName);
$action = $this->actions[$this->method];
return $action ? $action.'_'.$routeName[0] : null;
}
/**
* Get controller name from namespace string
*
* @param $string
* @return mixed
*/
protected function getControllerName($string)
{
$controllerArray = explode('\\', $string);
return end($controllerArray);
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment