permissions systems 2.0

This commit is contained in:
2019-01-09 07:47:32 -06:00
parent 6fcb2d5edf
commit 21b4a7ce81
10 changed files with 121 additions and 65 deletions

View File

@@ -0,0 +1,42 @@
<?php
namespace App\Http\Middleware;
use Closure;
class RequireRole
{
/**
* Handle an incoming request.
*
* @param \Illuminate\Http\Request $request
* @param \Closure $next
* @return mixed
*/
public function handle($request, Closure $next, $role)
{
$confirmed = false;
$ranking = [
'None' => 0,
'Guest' => 1,
'User' => 2,
'Admin' => 3,
'SuperUser' => 4,
];
$check = UserPermission::where('character_id', auth()->user()->character_id)->get(['role']);
if(!isset($check[0]->role)) {
abort(403, "You don't any roles. You don't belong here.");
}
if($ranking[$check->permission] >= $ranking[$role]) {
$confirmed = true;
}
abort_unless(auth()->check() && $confirmed, 403, "You don't have the correct role to be in this area.");
return $next($request);
}
}