- Add DEPLOYMENT_HANDOFF.md for client IT team with full production steps - Fix ApiKeyMiddleware: correct Response import and fail-closed on unset key - Remove committed Bridge API secret from all tracked docs - Document seed, admin provisioning, WP user sync, Kavenegar, and wp-config hardening - Reformat AGENT.md, README.md, CLIENT_DELIVERY.md to consistent structure
35 lines
941 B
PHP
35 lines
941 B
PHP
<?php
|
|
|
|
namespace App\Http\Middleware;
|
|
|
|
use Closure;
|
|
use Illuminate\Http\Request;
|
|
use Symfony\Component\HttpFoundation\Response;
|
|
|
|
class ApiKeyMiddleware
|
|
{
|
|
public function handle(Request $request, Closure $next): Response
|
|
{
|
|
$apiKey = config('ifnex.api_key');
|
|
|
|
if (empty($apiKey) || in_array($apiKey, ['change-me', 'change-this-secret-key'], true)) {
|
|
return response()->json([
|
|
'message' => 'API Key is not configured. Set IFNEX_API_KEY in .env.',
|
|
], 500);
|
|
}
|
|
|
|
$provided = $request->header('Authorization');
|
|
|
|
if (!$provided || !str_starts_with($provided, 'Bearer ')) {
|
|
return response()->json(['message' => 'Unauthorized'], 401);
|
|
}
|
|
|
|
$token = substr($provided, 7);
|
|
|
|
if (!hash_equals($apiKey, $token)) {
|
|
return response()->json(['message' => 'Forbidden'], 403);
|
|
}
|
|
|
|
return $next($request);
|
|
}
|
|
} |