CheckAuth.php 2.3 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374
  1. <?php
  2. declare (strict_types = 1);
  3. namespace app\txx\middleware;
  4. use app\txx\common\Sign;
  5. use think\facade\Db;
  6. use think\Response;
  7. use think\facade\Log;
  8. class CheckAuth
  9. {
  10. /**
  11. * 处理请求
  12. *
  13. * @param \think\Request $request
  14. * @param \Closure $next
  15. * @return Response
  16. */
  17. public function handle($request, \Closure $next)
  18. {
  19. $request->isCx=0;
  20. $request->uid=0;
  21. $request->uname='';
  22. $param = $request->post();
  23. $header = $request->header();
  24. Log::write("IPAddr:".$request->server("REMOTE_ADDR"),"info");
  25. Log::write("Action:".$request->server("REQUEST_URI"),"info");
  26. Log::write("param:".json_encode($param),"info");
  27. Log::write("header:".json_encode($header),"info");
  28. if(!isset($param['token'])||$param['token']==''){
  29. Log::write("Action:".$request->server("REQUEST_URI"),"info");
  30. $check =$this->check($header,$param);
  31. if($check['code']==1){
  32. return json_show(104,$check['msg']);
  33. }
  34. }else{
  35. $acct =VerifyTokens($param['token']);
  36. if(!isset($acct['code']) || $acct['code']!=0){
  37. return json_show(102,$acct['message']);
  38. }
  39. $request->uid=isset($acct['data']['user']['id']) ?$acct['data']['user']['id']:"";
  40. $request->uname=isset($acct['data']['user']['nickname']) ?$acct['data']['user']['nickname']:"";
  41. $request->isCx=1;
  42. }
  43. $response = $next($request);
  44. return $response;
  45. }
  46. public function end(Response $response)
  47. {
  48. }
  49. /**数据接口签名验证
  50. * @param $data
  51. * @param $param
  52. * @return array
  53. */
  54. private function check($data,$param){
  55. //check sign
  56. if (!isset($data['appid']) || !$data['appid']) {
  57. return ['code'=>1,'msg'=>'发送的应用参数不存在'];
  58. }
  59. $appinf =Db::name("act_company")->where(["app_id"=>$data['appid'],"is_del"=>0,"status"=>1])->findOrEmpty();
  60. if(empty($appinf)){
  61. return ['code'=>1,'msg'=>'发送的应用参数错误'];
  62. }
  63. $mege=["appid"=>$data['appid'],"noce"=>$data['noce']??'',"sign"=>$data['sign']??'',"timestamp"=>$data['timestamp']??''];
  64. $value =array_merge($mege,$param);
  65. $Sign=new Sign($appinf['app_id'],$appinf['app_key']);
  66. $result =$Sign->verifySign($value);
  67. return $result;
  68. }
  69. }