【问题标题】:Trying to set up a multi-tenancy with Request data identification on Laravel 9.3尝试在 Laravel 9.3 上设置带有请求数据标识的多租户
【发布时间】:2023-01-16 23:25:22
【问题描述】:

我正在尝试在 Laravel 上设置带有请求数据标识的多租户操作,但我找不到任何相关信息。

跟着这个快速入门就这么简单吗https://tenancyforlaravel.com/docs/v3/quickstart

然后按照这一步? https://tenancyforlaravel.com/docs/v3/tenant-identification/#Request-data-identification:~:text=public%20static%20property).-,Request%20data%20identification,-You%20might%20want

所以改变我的帐篷路线

<?php

declare(strict_types=1);

use Illuminate\Support\Facades\Route;
use Stancl\Tenancy\Middleware\InitializeTenancyByDomain;
use Stancl\Tenancy\Middleware\PreventAccessFromCentralDomains;

/*
|--------------------------------------------------------------------------
| Tenant Routes
|--------------------------------------------------------------------------
|
| Here you can register the tenant routes for your application.
| These routes are loaded by the TenantRouteServiceProvider.
|
| Feel free to customize them however you want. Good luck!
|
*/

Route::middleware([
    'web',
    InitializeTenancyByDomain::class,
    PreventAccessFromCentralDomains::class,
])->group(function () {
    Route::get('/', function () {
        return 'This is your multi-tenant application. The id of the current tenant is ' . tenant('id');
    });
});

对此:

<?php

declare(strict_types=1);

use Illuminate\Support\Facades\Route;
use Stancl\Tenancy\Middleware\InitializeTenancyByRequestData;
use Stancl\Tenancy\Middleware\PreventAccessFromCentralDomains;

/*
|--------------------------------------------------------------------------
| Tenant Routes
|--------------------------------------------------------------------------
|
| Here you can register the tenant routes for your application.
| These routes are loaded by the TenantRouteServiceProvider.
|
| Feel free to customize them however you want. Good luck!
|
*/

Route::middleware([
    'web',
    InitializeTenancyByRequestData::class,
    PreventAccessFromCentralDomains::class,
])->group(function () {
    Route::get('/', function () {
        return 'This is your multi-tenant application. The id of the current tenant is ' . tenant('id');
    });
});

【问题讨论】:

    标签: php laravel multi-tenant


    【解决方案1】:

    接下来您应该做的是创建一个中间件,您可以在其中验证标头中的 x-tenant 或作为文档中建议的查询参数。

    我附加了一个示例来使用标头进行操作,JWT 将是这样的:

    /**
         * Handle an incoming request.
         *
         * @param  IlluminateHttpRequest  $request
         * @param  Closure(IlluminateHttpRequest): (IlluminateHttpResponse|IlluminateHttpRedirectResponse)  $next
         * @return IlluminateHttpResponse|IlluminateHttpRedirectResponse
         */
        public function handle(Request $request, Closure $next)
        {
            if($user = JWTAuth::parseToken()->authenticate())
            {
                if ($user->global_id != $request->header('x-tenant'))
                {
                    return response()->json(['errors' => 'You do not have access to this tenant'], 401);
                }
    
                return $next($request);
            }
        }
    

    当然,您必须根据应用的性质考虑其他安全方面的问题。

    【讨论】:

      猜你喜欢
      • 2011-11-24
      • 1970-01-01
      • 2020-11-22
      • 2019-10-28
      • 2015-03-20
      • 2023-03-20
      • 2021-07-04
      • 2020-06-18
      • 2020-11-27
      相关资源
      最近更新 更多