Deploy Ladill Hosting / deploy (push) Successful in 1m29s
Expose authenticated service endpoints for assigning, listing, renewing, and managing hosting accounts from the platform, with tests and deploy docs. Co-authored-by: Cursor <cursoragent@cursor.com>
38 lines
1.0 KiB
PHP
38 lines
1.0 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Middleware;
|
|
|
|
use Closure;
|
|
use Illuminate\Http\Request;
|
|
use Symfony\Component\HttpFoundation\Response;
|
|
|
|
/**
|
|
* Generic service-to-service auth for internal APIs. Validates the bearer token
|
|
* against per-consumer keys in config("{namespace}.service_api_keys").
|
|
*/
|
|
class AuthenticateService
|
|
{
|
|
public function handle(Request $request, Closure $next, string $namespace = 'platform'): Response
|
|
{
|
|
$token = (string) $request->bearerToken();
|
|
$caller = null;
|
|
|
|
if ($token !== '') {
|
|
foreach ((array) config("{$namespace}.service_api_keys", []) as $name => $key) {
|
|
if (is_string($key) && $key !== '' && hash_equals($key, $token)) {
|
|
$caller = $name;
|
|
break;
|
|
}
|
|
}
|
|
}
|
|
|
|
if ($caller === null) {
|
|
return response()->json(['error' => 'Unauthorized.'], 401);
|
|
}
|
|
|
|
$request->attributes->set('service_caller', $caller);
|
|
|
|
return $next($request);
|
|
}
|
|
}
|