| 12345678910111213141516171819202122232425262728293031323334 |
- <?php
- namespace App\Http\Middleware;
- use App\Services\Access\AccessService;
- use Closure;
- use Illuminate\Http\Request;
- use Symfony\Component\HttpFoundation\Response;
- class EnsureRoutePermission
- {
- public function __construct(private readonly AccessService $accessService)
- {
- }
- public function handle(Request $request, Closure $next): Response
- {
- $user = $request->user();
- $routeName = $request->route()?->getName();
- if (!$user || !$routeName || !$this->accessService->routePermission($routeName)) {
- return $next($request);
- }
- // Compatibility while tests and old runtime paths still create users with only legacy role slugs.
- if (!$user->role_id) {
- return $next($request);
- }
- abort_unless($this->accessService->canAccessRoute($user, $routeName), 403);
- return $next($request);
- }
- }
|