Completed
Push — 2.0 ( b837a7...689dde )
by Nicolas
14:08
created

AuthorisedApiTokenAdmin::parseToken()   A

Complexity

Conditions 1
Paths 1

Size

Total Lines 4
Code Lines 2

Duplication

Lines 0
Ratio 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
c 1
b 0
f 0
dl 0
loc 4
rs 10
cc 1
eloc 2
nc 1
nop 1
1
<?php namespace Modules\User\Http\Middleware;
2
3
use Illuminate\Http\Request;
4
use Illuminate\Http\Response;
5
use Modules\User\Repositories\UserTokenRepository;
6
7
class AuthorisedApiTokenAdmin
8
{
9
    /**
10
     * @var UserTokenRepository
11
     */
12
    private $userToken;
13
14
    public function __construct(UserTokenRepository $userToken)
15
    {
16
        $this->userToken = $userToken;
17
    }
18
19
    public function handle(Request $request, \Closure $next)
20
    {
21
        if ($request->header('Authorization') === null) {
22
            return new Response('Forbidden', 403);
23
        }
24
25
        if ($this->isValidToken($request->header('Authorization')) === false) {
26
            return new Response('Forbidden', 403);
27
        }
28
29
        return $next($request);
30
    }
31
32
    private function isValidToken($token)
33
    {
34
        $found = $this->userToken->findByAttributes(['access_token' => $this->parseToken($token)]);
35
36
        if ($found === null) {
37
            return false;
38
        }
39
40
        if ($found->user->hasRoleName('admin') === false) {
41
            return false;
42
        }
43
44
        return true;
45
    }
46
47
    private function parseToken($token)
48
    {
49
        return str_replace('Bearer ', '', $token);
50
    }
51
}
52