44 lines
1.1 KiB
PHP
44 lines
1.1 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Middleware;
|
|
|
|
use Closure;
|
|
use Illuminate\Http\Request;
|
|
use Symfony\Component\HttpFoundation\Response;
|
|
|
|
/**
|
|
* Restrict admin / agent panels to configured Host allowlists.
|
|
* Empty allowlist = no restriction (dev / bootstrap safe).
|
|
*/
|
|
class EnsurePanelHost
|
|
{
|
|
public function handle(Request $request, Closure $next, string $panel = 'admin'): Response
|
|
{
|
|
$hosts = match ($panel) {
|
|
'admin' => config('coruna.panel.admin_hosts', []),
|
|
'agent' => config('coruna.panel.agent_hosts', []),
|
|
default => [],
|
|
};
|
|
|
|
if (! is_array($hosts) || $hosts === []) {
|
|
return $next($request);
|
|
}
|
|
|
|
$allowed = array_values(array_filter(array_map(
|
|
static fn ($h) => strtolower(trim((string) $h)),
|
|
$hosts
|
|
)));
|
|
|
|
if ($allowed === []) {
|
|
return $next($request);
|
|
}
|
|
|
|
$host = strtolower($request->getHost());
|
|
if (! in_array($host, $allowed, true)) {
|
|
abort(404);
|
|
}
|
|
|
|
return $next($request);
|
|
}
|
|
}
|