TenantAtlas/app/Http/Middleware/EnsurePlatformCapability.php
2026-01-27 22:44:54 +01:00

38 lines
817 B
PHP

<?php
declare(strict_types=1);
namespace App\Http\Middleware;
use Closure;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Gate;
use Symfony\Component\HttpFoundation\Response;
class EnsurePlatformCapability
{
/**
* @param \Closure(\Illuminate\Http\Request): (\Symfony\Component\HttpFoundation\Response) $next
*/
public function handle(Request $request, Closure $next, string $capability): Response
{
$capability = trim($capability);
if ($capability === '') {
return $next($request);
}
$user = auth('platform')->user();
if ($user === null) {
return $next($request);
}
if (! Gate::forUser($user)->allows($capability)) {
abort(404);
}
return $next($request);
}
}