EnsureRoutePermission.php 1.2 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243
  1. <?php
  2. namespace App\Http\Middleware;
  3. use App\Services\Access\AccessService;
  4. use Closure;
  5. use Illuminate\Http\Request;
  6. use Symfony\Component\HttpFoundation\Response;
  7. class EnsureRoutePermission
  8. {
  9. public function __construct(private readonly AccessService $accessService)
  10. {
  11. }
  12. public function handle(Request $request, Closure $next): Response
  13. {
  14. $user = $request->user();
  15. $routeName = $request->route()?->getName();
  16. $routePermission = $routeName === 'import.create' && $request->input('type') === 'catalog'
  17. ? 'catalog.import'
  18. : $this->accessService->routePermission($routeName);
  19. if (!$user || !$routeName || !$routePermission) {
  20. return $next($request);
  21. }
  22. // Compatibility while tests and old runtime paths still create users with only legacy role slugs.
  23. if (!$user->role_id) {
  24. return $next($request);
  25. }
  26. abort_unless(
  27. is_array($routePermission)
  28. ? $this->accessService->canAny($user, $routePermission)
  29. : $this->accessService->can($user, $routePermission),
  30. 403
  31. );
  32. return $next($request);
  33. }
  34. }