<?php
namespace App\Http\Middleware;
use App\Classes\SendResponse;
use App\UserClient;
use Closure;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Log;
class Partners
{
/**
* Handle an incoming request.
*
* @param \Illuminate\Http\Request $request
* @param \Closure(\Illuminate\Http\Request): (\Illuminate\Http\Response|\Illuminate\Http\RedirectResponse) $next
* @return \Illuminate\Http\Response|\Illuminate\Http\RedirectResponse
*/
public function handle(Request $request, Closure $next)
{
// Obtém o valor do cabeçalho Authorization
$authHeader = $request->header('Authorization');
// Verifica se o cabeçalho Authorization está presente
if ($authHeader && preg_match('/Bearer\s(\S+)/', $authHeader, $matches)) {
$token = $matches[1];
$apps = UserClient::query()->select('client_key', 'private_key')->get();
$client_key = $this->isValidToken($apps, $token);
if (!$client_key) return SendResponse::errorResp401unauthenticated('Chave de encriptação invalida', 'Invalid Encryption Key');
$app = UserClient::query()->where('client_key', $client_key)->first();
if (!$app) return SendResponse::errorResp401unauthenticated();
} else {
return SendResponse::errorResp401unauthorized();
}
return $next($request);
}
private function isValidToken($apps, $token)
{
$sizeOfclients = sizeof($apps);
if ($sizeOfclients > 0) {
foreach ($apps as $app) {
try {
$decryptedAPIKey = $this->decryptString($token, $app->private_key);
return $decryptedAPIKey;
} catch (\Throwable $th) {
continue;
}
}
}
return false;
}
public function decryptString($encryptedData, $privateKey)
{
openssl_private_decrypt(base64_decode($encryptedData), $decryptedData, $privateKey);
return $decryptedData;
}
}