2021-08-02 17:02:25 -04:00
|
|
|
<?php
|
|
|
|
|
|
|
|
namespace BookStack\Http\Middleware;
|
|
|
|
|
|
|
|
use BookStack\Auth\Access\LoginService;
|
|
|
|
use BookStack\Auth\Access\Mfa\MfaSession;
|
|
|
|
use Closure;
|
|
|
|
|
|
|
|
class AuthenticatedOrPendingMfa
|
|
|
|
{
|
|
|
|
protected $loginService;
|
|
|
|
protected $mfaSession;
|
|
|
|
|
|
|
|
public function __construct(LoginService $loginService, MfaSession $mfaSession)
|
|
|
|
{
|
|
|
|
$this->loginService = $loginService;
|
|
|
|
$this->mfaSession = $mfaSession;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Handle an incoming request.
|
|
|
|
*
|
2021-08-21 10:49:40 -04:00
|
|
|
* @param \Illuminate\Http\Request $request
|
|
|
|
* @param \Closure $next
|
|
|
|
*
|
2021-08-02 17:02:25 -04:00
|
|
|
* @return mixed
|
|
|
|
*/
|
|
|
|
public function handle($request, Closure $next)
|
|
|
|
{
|
|
|
|
$user = auth()->user();
|
|
|
|
$loggedIn = $user !== null;
|
|
|
|
$lastAttemptUser = $this->loginService->getLastLoginAttemptUser();
|
|
|
|
|
|
|
|
if ($loggedIn || ($lastAttemptUser && $this->mfaSession->isPendingMfaSetup($lastAttemptUser))) {
|
|
|
|
return $next($request);
|
|
|
|
}
|
|
|
|
|
2021-08-21 10:14:24 -04:00
|
|
|
return redirect()->to(url('/login'));
|
2021-08-02 17:02:25 -04:00
|
|
|
}
|
|
|
|
}
|