| 123456789101112131415161718192021222324252627282930313233343536373839 |
- <?php
- namespace App\Http\Middleware;
- use App\Services\Access\AccessService;
- use Closure;
- use Illuminate\Http\Request;
- use Symfony\Component\HttpFoundation\Response;
- class EnsureUserHasRole
- {
- public function __construct(private readonly AccessService $accessService)
- {
- }
- /**
- * Handle an incoming request.
- *
- * @param Request $request
- * @param Closure $next
- * @param mixed ...$roles
- * @return Response
- */
- public function handle(Request $request, Closure $next, ... $roles): Response
- {
- $user = $request->user();
- $routeName = $request->route()?->getName();
- $hasRoutePermission = $user && $routeName === 'import.create' && $request->input('type') === 'catalog'
- ? $this->accessService->can($user, 'catalog.import')
- : ($user && $this->accessService->canAccessRoute($user, $routeName));
- if ($user?->hasRole($roles) || $hasRoutePermission) {
- return $next($request);
- }
- abort(403);
- }
- }
|