namespace App\Http;
use Illuminate\Foundation\Http\Kernel as HttpKernel;
class Kernel extends HttpKernel
{
/**
* The application's global HTTP middleware stack.
*
* These middleware are run during every request to your application.
*
* @var array
*/
protected $middleware = [
// \App\Http\Middleware\TrustHosts::class,
\App\Http\Middleware\TrustProxies::class,
\Fruitcake\Cors\HandleCors::class,
\App\Http\Middleware\PreventRequestsDuringMaintenance::class,
\Illuminate\Foundation\Http\Middleware\ValidatePostSize::class,
\App\Http\Middleware\TrimStrings::class,
\Illuminate\Foundation\Http\Middleware\ConvertEmptyStringsToNull::class,
];
/**
* The application's route middleware groups.
*
* @var array>
*/
protected $middlewareGroups = [
'web' => [
\App\Http\Middleware\EncryptCookies::class,
\Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class,
\Illuminate\Session\Middleware\StartSession::class,
// \Illuminate\Session\Middleware\AuthenticateSession::class,
\Illuminate\View\Middleware\ShareErrorsFromSession::class,
\App\Http\Middleware\VerifyCsrfToken::class,
\Illuminate\Routing\Middleware\SubstituteBindings::class,
],
'api' => [
// \Laravel\Sanctum\Http\Middleware\EnsureFrontendRequestsAreStateful::class,
'throttle:api',
\Illuminate\Routing\Middleware\SubstituteBindings::class,
],
];
/**
* The application's route middleware.
*
* These middleware may be assigned to groups or used individually.
*
* @var array
*/
protected $routeMiddleware = [
'auth' => \App\Http\Middleware\Authenticate::class,
'admin.auth' => \Modules\Admin\Http\Middleware\RedirectIfNotAdmin::class, // 添加这行
'auth.basic' => \Illuminate\Auth\Middleware\AuthenticateWithBasicAuth::class,
'cache.headers' => \Illuminate\Http\Middleware\SetCacheHeaders::class,
'can' => \Illuminate\Auth\Middleware\Authorize::class,
'guest' => \App\Http\Middleware\RedirectIfAuthenticated::class,
'password.confirm' => \Illuminate\Auth\Middleware\RequirePassword::class,
'signed' => \Illuminate\Routing\Middleware\ValidateSignature::class,
'throttle' => \Illuminate\Routing\Middleware\ThrottleRequests::class,
'verified' => \Illuminate\Auth\Middleware\EnsureEmailIsVerified::class,
];
}
想象一下,学校里有很多“规则”要遵守:
Laravel的这个Kernel.php
文件就像是学校的“规则手册”,它规定了:
当你在网上买了一个包裹,这个包裹在送到你手上之前,要经过很多“检查站”:
Laravel的中间件就像是这些“检查站”:
想象一场接力赛,中间件就像是接力赛中的“检查员”:
Laravel的中间件就是按照这个顺序,一个接一个地处理请求和响应,确保所有规则都被遵守。
// 所有人都要遵守的规则(全局中间件)
protected $middleware = [
\App\Http\Middleware\TrustProxies::class, // 信任代理服务器(就像信任学校保安)
\Fruitcake\Cors\HandleCors::class, // 处理跨域请求(就像允许校外人员来参观)
\App\Http\Middleware\TrimStrings::class, // 清理多余空格(就像整理书包)
];
// 不同场所的规则(中间件组)
'web' => [ // 网页请求的规则
\App\Http\Middleware\EncryptCookies::class, // 给饼干加密(保护小秘密)
\Illuminate\Session\Middleware\StartSession::class, // 开启会话(就像签到)
\App\Http\Middleware\VerifyCsrfToken::class, // 验证CSRF令牌(防止坏人冒充你)
],
'api' => [ // API请求的规则
'throttle:api', // 限制请求频率(就像限制提问次数)
];
// 针对特定人的规则(路由中间件)
'auth' => \App\Http\Middleware\Authenticate::class, // 必须登录(就像要有学生证)
'admin.auth' => \Modules\Admin\Http\Middleware\RedirectIfNotAdmin::class, // 必须是管理员(就像校长才能进校长办公室)
Laravel的中间件就像是数字世界的“规则警察”,它们站在请求和响应的“十字路口”,确保每个请求都遵守规则,每个响应都安全可靠。就像学校需要规则来维持秩序一样,Laravel需要中间件来保证应用的安全和稳定!