mirror of
				https://github.com/invoiceninja/invoiceninja.git
				synced 2025-10-26 15:22:52 -04:00 
			
		
		
		
	* Adopt Laravel coding style The Laravel framework adopts the PSR-2 coding style with some additions. Laravel apps *should* adopt this coding style as well. However, Shift allows you to customize the adopted coding style by adding your own [PHP CS Fixer][1] `.php_cs` config to your project. You may use [Shift's .php_cs][2] file as a base. [1]: https://github.com/FriendsOfPHP/PHP-CS-Fixer [2]: https://gist.github.com/laravel-shift/cab527923ed2a109dda047b97d53c200 * Shift bindings PHP 5.5.9+ adds the new static `class` property which provides the fully qualified class name. This is preferred over using class name strings as these references are checked by the parser. * Shift core files * Shift to Throwable * Add laravel/ui dependency * Unindent vendor mail templates * Shift config files * Default config files In an effort to make upgrading the constantly changing config files easier, Shift defaulted them so you can review the commit diff for changes. Moving forward, you should use ENV variables or create a separate config file to allow the core config files to remain automatically upgradeable. * Shift Laravel dependencies * Shift cleanup * Upgrade to Laravel 7 Co-authored-by: Laravel Shift <shift@laravelshift.com>
		
			
				
	
	
		
			84 lines
		
	
	
		
			2.4 KiB
		
	
	
	
		
			PHP
		
	
	
	
	
	
			
		
		
	
	
			84 lines
		
	
	
		
			2.4 KiB
		
	
	
	
		
			PHP
		
	
	
	
	
	
| <?php
 | |
| /**
 | |
|  * Invoice Ninja (https://invoiceninja.com).
 | |
|  *
 | |
|  * @link https://github.com/invoiceninja/invoiceninja source repository
 | |
|  *
 | |
|  * @copyright Copyright (c) 2020. Invoice Ninja LLC (https://invoiceninja.com)
 | |
|  *
 | |
|  * @license https://opensource.org/licenses/AAL
 | |
|  */
 | |
| 
 | |
| namespace App\Http\Middleware;
 | |
| 
 | |
| use App\Events\User\UserLoggedIn;
 | |
| use App\Models\CompanyToken;
 | |
| use App\Models\User;
 | |
| use App\Utils\Ninja;
 | |
| use Closure;
 | |
| 
 | |
| class TokenAuth
 | |
| {
 | |
|     /**
 | |
|      * Handle an incoming request.
 | |
|      *
 | |
|      * @param  \Illuminate\Http\Request  $request
 | |
|      * @param  \Closure  $next
 | |
|      * @return mixed
 | |
|      */
 | |
|     public function handle($request, Closure $next)
 | |
|     {
 | |
|         if ($request->header('X-API-TOKEN') && ($company_token = CompanyToken::with(['user', 'company'])->whereRaw('BINARY `token`= ?', [$request->header('X-API-TOKEN')])->first())) {
 | |
|             $user = $company_token->user;
 | |
| 
 | |
|             $error = [
 | |
|                 'message' => 'User inactive',
 | |
|                 'errors' => new \stdClass,
 | |
|             ];
 | |
|             //user who once existed, but has been soft deleted
 | |
|             if (! $user) {
 | |
|                 return response()->json($error, 403);
 | |
|             }
 | |
| 
 | |
|             /*
 | |
|             |
 | |
|             | Necessary evil here: As we are authenticating on CompanyToken,
 | |
|             | we need to link the company to the user manually. This allows
 | |
|             | us to decouple a $user and their attached companies completely.
 | |
|             |
 | |
|             */
 | |
|             $user->setCompany($company_token->company);
 | |
| 
 | |
|             config(['ninja.company_id' => $company_token->company->id]);
 | |
| 
 | |
|             app('queue')->createPayloadUsing(function () use ($company_token) {
 | |
|                 return ['db' => $company_token->company->db];
 | |
|             });
 | |
| 
 | |
|             //user who once existed, but has been soft deleted
 | |
|             if ($user->company_user->is_locked) {
 | |
|                 $error = [
 | |
|                     'message' => 'User access locked',
 | |
|                     'errors' => new \stdClass,
 | |
|                 ];
 | |
| 
 | |
|                 return response()->json($error, 403);
 | |
|             }
 | |
| 
 | |
|             //stateless, don't remember the user.
 | |
|             auth()->login($user, false);
 | |
| 
 | |
|             event(new UserLoggedIn($user, $company_token->company, Ninja::eventVars()));
 | |
|         } else {
 | |
|             $error = [
 | |
|                 'message' => 'Invalid token',
 | |
|                 'errors' => new \stdClass,
 | |
|             ];
 | |
| 
 | |
|             return response()->json($error, 403);
 | |
|         }
 | |
| 
 | |
|         return $next($request);
 | |
|     }
 | |
| }
 |