<?php
namespace App\Http\Middleware;
use Closure;
use Illuminate\Http\Request;
/**
* Middleware disallow users not have admin permissions
*/
class OnlyAdmin
{
/**
* Handle an incoming request.
*
* @param \Illuminate\Http\Request $request
* @param \Closure $next
* @return mixed
*/
public function handle(Request $request, Closure $next)
{
if (auth())
if ($request->user()->is_admin)
return $next($request);
return response()->json([], 403);
}
}
|