|
@@ -2,13 +2,61 @@
|
2
|
2
|
|
3
|
3
|
namespace Luticate\Auth\Business;
|
4
|
4
|
|
|
5
|
+use Illuminate\Http\Request;
|
5
|
6
|
use Luticate\Utils\LuBusiness;
|
6
|
7
|
use Luticate\Auth\DataAccess\LuticateUsersDataAccess;
|
7
|
8
|
use Luticate\Auth\DBO\LuticateUsersDbo;
|
|
9
|
+use Luticate\Utils\LuRoute;
|
8
|
10
|
|
9
|
11
|
class LuticateUsersBusiness extends LuBusiness {
|
|
12
|
+ /**
|
|
13
|
+ * @var LuticateUsersDbo
|
|
14
|
+ */
|
|
15
|
+ private static $_currentUser;
|
|
16
|
+
|
|
17
|
+ const TOKEN_HEADER = "X-Authentication";
|
|
18
|
+
|
10
|
19
|
public function __construct()
|
11
|
20
|
{
|
12
|
21
|
$this->dataAccess = new LuticateUsersDataAccess();
|
13
|
22
|
}
|
|
23
|
+
|
|
24
|
+ public static function getCurrentUser()
|
|
25
|
+ {
|
|
26
|
+ return self::$_currentUser;
|
|
27
|
+ }
|
|
28
|
+
|
|
29
|
+ /**
|
|
30
|
+ * @param $permissions string[]
|
|
31
|
+ * @param $request Request
|
|
32
|
+ * @return bool
|
|
33
|
+ */
|
|
34
|
+ public static function authFilter($permissions, $request)
|
|
35
|
+ {
|
|
36
|
+ $token = $request->header(self::TOKEN_HEADER);
|
|
37
|
+ if ($token == null)
|
|
38
|
+ {
|
|
39
|
+ return false;
|
|
40
|
+ }
|
|
41
|
+ $data = JwtHelper::decode($token);
|
|
42
|
+ if ($data == null)
|
|
43
|
+ {
|
|
44
|
+ return false;
|
|
45
|
+ }
|
|
46
|
+ $user_id = $data[JwtHelper::USER_KEY];
|
|
47
|
+
|
|
48
|
+ foreach ($permissions as $permission) {
|
|
49
|
+ if (!LuticatePermissionsBusiness::getUserPermission($user_id, $permission)) {
|
|
50
|
+ return false;
|
|
51
|
+ }
|
|
52
|
+ }
|
|
53
|
+
|
|
54
|
+ $user = LuticateUsersBusiness::getById($user_id);
|
|
55
|
+ if ($user == null)
|
|
56
|
+ {
|
|
57
|
+ return false;
|
|
58
|
+ }
|
|
59
|
+ self::$_currentUser = $user;
|
|
60
|
+ return true;
|
|
61
|
+ }
|
14
|
62
|
}
|