2020-10-08 15:38:36 +02:00
|
|
|
<?php
|
|
|
|
|
|
|
|
namespace App\Http\Middleware;
|
|
|
|
|
|
|
|
use Closure;
|
2021-12-02 13:15:53 +01:00
|
|
|
use App\Models\User;
|
2020-10-08 15:38:36 +02:00
|
|
|
use Carbon\Carbon;
|
|
|
|
use Illuminate\Http\Response;
|
|
|
|
use Illuminate\Support\Facades\Auth;
|
2021-10-15 23:46:21 +02:00
|
|
|
use Illuminate\Support\Facades\Log;
|
2020-10-08 15:38:36 +02:00
|
|
|
|
2021-11-17 23:37:16 +01:00
|
|
|
class KickOutInactiveUser
|
2020-10-08 15:38:36 +02:00
|
|
|
{
|
|
|
|
/**
|
|
|
|
* Handle an incoming request.
|
|
|
|
*
|
|
|
|
* @param \Illuminate\Http\Request $request
|
|
|
|
* @param \Closure $next
|
|
|
|
* @return mixed
|
|
|
|
*/
|
2022-03-24 14:58:30 +01:00
|
|
|
public function handle($request, Closure $next, ...$quards)
|
2020-10-08 15:38:36 +02:00
|
|
|
{
|
2022-03-24 14:58:30 +01:00
|
|
|
// We do not track activity of:
|
|
|
|
// - Guest
|
|
|
|
// - User authenticated against a bearer token
|
|
|
|
// - User authenticated via a reverse-proxy
|
|
|
|
if (Auth::guest() || $request->bearerToken() || config('auth.defaults.guard') === 'reverse-proxy-guard') {
|
2020-10-08 15:38:36 +02:00
|
|
|
return $next($request);
|
|
|
|
}
|
|
|
|
|
2021-11-17 23:37:16 +01:00
|
|
|
$user = Auth::user();
|
2020-10-08 15:38:36 +02:00
|
|
|
$now = Carbon::now();
|
2020-10-09 13:35:03 +02:00
|
|
|
$inactiveFor = $now->diffInSeconds(Carbon::parse($user->last_seen_at));
|
2020-10-08 15:38:36 +02:00
|
|
|
|
|
|
|
// Fetch all setting values
|
2021-12-01 13:47:20 +01:00
|
|
|
$settingService = resolve('App\Services\SettingService');
|
2021-10-29 21:51:58 +02:00
|
|
|
$kickUserAfterXSecond = intval($settingService->get('kickUserAfter')) * 60;
|
2020-10-09 13:35:03 +02:00
|
|
|
|
|
|
|
// If user has been inactive longer than the allowed inactivity period
|
|
|
|
if ($kickUserAfterXSecond > 0 && $inactiveFor > $kickUserAfterXSecond) {
|
|
|
|
|
2020-10-08 15:38:36 +02:00
|
|
|
$user->last_seen_at = $now->format('Y-m-d H:i:s');
|
|
|
|
$user->save();
|
2021-11-17 23:37:16 +01:00
|
|
|
|
2021-10-29 21:51:58 +02:00
|
|
|
Log::notice('Inactive user detected, authentication rejected');
|
2020-10-08 15:38:36 +02:00
|
|
|
|
|
|
|
return response()->json(['message' => 'unauthorised'], Response::HTTP_UNAUTHORIZED);
|
|
|
|
}
|
|
|
|
|
|
|
|
return $next($request);
|
|
|
|
}
|
2021-10-29 21:51:58 +02:00
|
|
|
}
|