EnsureUserHasRole.php 1.0 KB

123456789101112131415161718192021222324252627282930313233343536373839
  1. <?php
  2. namespace App\Http\Middleware;
  3. use App\Services\Access\AccessService;
  4. use Closure;
  5. use Illuminate\Http\Request;
  6. use Symfony\Component\HttpFoundation\Response;
  7. class EnsureUserHasRole
  8. {
  9. public function __construct(private readonly AccessService $accessService)
  10. {
  11. }
  12. /**
  13. * Handle an incoming request.
  14. *
  15. * @param Request $request
  16. * @param Closure $next
  17. * @param mixed ...$roles
  18. * @return Response
  19. */
  20. public function handle(Request $request, Closure $next, ... $roles): Response
  21. {
  22. $user = $request->user();
  23. $routeName = $request->route()?->getName();
  24. $hasRoutePermission = $user && $routeName === 'import.create' && $request->input('type') === 'catalog'
  25. ? $this->accessService->can($user, 'catalog.import')
  26. : ($user && $this->accessService->canAccessRoute($user, $routeName));
  27. if ($user?->hasRole($roles) || $hasRoutePermission) {
  28. return $next($request);
  29. }
  30. abort(403);
  31. }
  32. }