<?php
namespace App\Http\Middleware;
use App\Classes\SendResponse;
use App\UserClient;
use Closure;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Log;
class PartnersV2
{
/**
* Handle an incoming request.
*
* @param \Illuminate\Http\Request $request
* @param \Closure(\Illuminate\Http\Request): (\Illuminate\Http\Response|\Illuminate\Http\RedirectResponse) $next
* @return \Illuminate\Http\Response|\Illuminate\Http\RedirectResponse
*/
public function handle(Request $request, Closure $next)
{
// Obtém o valor do cabeçalho Authorization
$authHeader = $request->header('Authorization');
$clientID = $request->header('X-Client-ID');
if (!$request->hasHeader('X-Client-ID')) return SendResponse::errorResp400('X-Client-ID nao existe', 'X-Client-ID does not exists');
// Verifica se o cabeçalho Authorization está presente
if ($authHeader && preg_match('/Bearer\s(\S+)/', $authHeader, $matches)) {
$token = $matches[1];
$client = UserClient::query()->whereNotNull('client_id')->where('client_id', $clientID)->select('client_key', 'private_key', 'client_id')->first();
if (!$client) return SendResponse::errorResp401unauthenticated('ID de cliente invalido', 'Invalid Client ID');
$client_key = $this->isValidToken($client, $token);
if (!$client_key) return SendResponse::errorResp401unauthenticated('Chave de encriptação invalida', 'Invalid Encryption Key');
// $app = UserClient::query()->where('client_key', $client_key)->first();
if ($client->client_key !== $client_key) return SendResponse::errorResp401unauthenticated();
} else {
return SendResponse::errorResp401unauthorized();
}
return $next($request);
}
private function isValidToken($client, $token)
{
try {
return $this->decryptString($token, $client->private_key);
} catch (\Throwable $th) {
return false;
}
}
public function decryptString($encryptedData, $privateKey)
{
openssl_private_decrypt(base64_decode($encryptedData), $decryptedData, $privateKey);
return $decryptedData;
}
}