Completed
Push — 2.0 ( b837a7...689dde )
by Nicolas
14:08
created

AuthorisedApiTokenAdmin   A

Complexity

Total Complexity 8

Size/Duplication

Total Lines 45
Duplicated Lines 0 %

Coupling/Cohesion

Components 1
Dependencies 3

Importance

Changes 1
Bugs 0 Features 0
Metric Value
wmc 8
c 1
b 0
f 0
lcom 1
cbo 3
dl 0
loc 45
rs 10

4 Methods

Rating   Name   Duplication   Size   Complexity  
A __construct() 0 4 1
A handle() 0 12 3
A isValidToken() 0 14 3
A parseToken() 0 4 1
1
<?php namespace Modules\User\Http\Middleware;
2
3
use Illuminate\Http\Request;
4
use Illuminate\Http\Response;
5
use Modules\User\Repositories\UserTokenRepository;
6
7
class AuthorisedApiTokenAdmin
8
{
9
    /**
10
     * @var UserTokenRepository
11
     */
12
    private $userToken;
13
14
    public function __construct(UserTokenRepository $userToken)
15
    {
16
        $this->userToken = $userToken;
17
    }
18
19
    public function handle(Request $request, \Closure $next)
20
    {
21
        if ($request->header('Authorization') === null) {
22
            return new Response('Forbidden', 403);
23
        }
24
25
        if ($this->isValidToken($request->header('Authorization')) === false) {
26
            return new Response('Forbidden', 403);
27
        }
28
29
        return $next($request);
30
    }
31
32
    private function isValidToken($token)
33
    {
34
        $found = $this->userToken->findByAttributes(['access_token' => $this->parseToken($token)]);
35
36
        if ($found === null) {
37
            return false;
38
        }
39
40
        if ($found->user->hasRoleName('admin') === false) {
41
            return false;
42
        }
43
44
        return true;
45
    }
46
47
    private function parseToken($token)
48
    {
49
        return str_replace('Bearer ', '', $token);
50
    }
51
}
52