enterprise-auth.middleware.ts 1.8 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152
  1. import { Context, Next } from 'hono';
  2. import { AuthService } from '../services/index';
  3. import { UserService } from '../../../user-module/src/services/index';
  4. import { AppDataSource } from '@d8d/shared-utils';
  5. import { AuthContext } from '@d8d/shared-types';
  6. import { parseWithAwait } from '@d8d/shared-utils';
  7. import { EnterpriseUserResponseSchema } from '../schemas/index';
  8. export async function enterpriseAuthMiddleware(c: Context<AuthContext>, next: Next) {
  9. try {
  10. const authHeader = c.req.header('Authorization');
  11. if (!authHeader) {
  12. return c.json({ message: 'Authorization header missing' }, 401);
  13. }
  14. const tokenParts = authHeader.split(' ');
  15. if (tokenParts.length !== 2 || tokenParts[0] !== 'Bearer') {
  16. return c.json({ message: 'Authorization header missing' }, 401);
  17. }
  18. const token = tokenParts[1];
  19. if (!token) {
  20. return c.json({ message: 'Token missing' }, 401);
  21. }
  22. const userService = new UserService(AppDataSource);
  23. const authService = new AuthService(userService);
  24. const decoded = authService.verifyToken(token);
  25. // 获取用户信息,包含企业关联
  26. const user = await userService.getUserWithCompany(decoded.id);
  27. if (!user) {
  28. return c.json({ message: 'User not found' }, 401);
  29. }
  30. // 验证用户是否是企业用户
  31. if (!user.companyId) {
  32. return c.json({ message: 'User is not an enterprise user' }, 403);
  33. }
  34. // 设置用户上下文(包含企业详情)
  35. const userData = await parseWithAwait(EnterpriseUserResponseSchema, user);
  36. c.set('user', userData);
  37. c.set('token', token);
  38. await next();
  39. } catch (error) {
  40. console.error('Enterprise authentication error:', error);
  41. return c.json({ message: 'Invalid token or insufficient permissions' }, 401);
  42. }
  43. }