SensitiveMiddleware.php 3.3 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495
  1. <?php
  2. declare(strict_types=1);
  3. namespace App\Middleware\Auth;
  4. use App\Tools\PublicData;
  5. use Hyperf\HttpServer\Contract\RequestInterface;
  6. use Hyperf\HttpServer\Contract\ResponseInterface as HttpResponse;
  7. use Psr\Container\ContainerInterface;
  8. use Psr\Http\Message\ResponseInterface;
  9. use Psr\Http\Message\ServerRequestInterface;
  10. use Psr\Http\Server\MiddlewareInterface;
  11. use Psr\Http\Server\RequestHandlerInterface;
  12. use Hyperf\HttpMessage\Stream\SwooleStream;
  13. use Hyperf\Di\Annotation\Inject;
  14. use Hyperf\Redis\Redis;
  15. //use Swoole\Http\Request;
  16. class SensitiveMiddleware implements MiddlewareInterface
  17. {
  18. protected ContainerInterface $container;
  19. protected RequestInterface $request;
  20. protected HttpResponse $response;
  21. #[Inject]
  22. protected Redis $redis;
  23. const STREAM_URL = [
  24. '/news/addArticle',
  25. '/news/updateArticle'
  26. ];
  27. public function __construct( RequestInterface $request, HttpResponse $response)
  28. {
  29. $this->request = $request;
  30. $this->response = $response;
  31. }
  32. public function process(ServerRequestInterface $request, RequestHandlerInterface $handler): ResponseInterface
  33. {
  34. $uri = $request->getUri();
  35. // 获取接口路径(不包含查询参数)
  36. $path = $uri->getPath();
  37. // var_dump("获取接口地址L:",$path);
  38. try {
  39. if(in_array($path,self::STREAM_URL)){
  40. $badWords = $this->redis->sMembers('black_word'); //黑名单
  41. $whiteWords = $this->redis->sMembers('white_word');//白名单
  42. // 获取所有请求参数并拼接成文本
  43. $params = $this->request->all();
  44. $concatenated = "";
  45. if($params){
  46. foreach ($params as $value) {
  47. if (is_array($value)) {
  48. // 如果值是数组,将数组元素用逗号连接
  49. $concatenated.= json_encode($value);
  50. } else {
  51. // 如果不是数组,直接拼接
  52. $concatenated.= $value;
  53. }
  54. }
  55. }
  56. // 遍历违禁词,检查是否在文本中存在
  57. foreach ($badWords as $badWord) {
  58. // 判断该违禁词是否在白名单中,如果在则跳过
  59. if (in_array($badWord, $whiteWords)) {
  60. continue;
  61. }
  62. if (str_contains($concatenated, $badWord)) {
  63. // 处理找到违禁词的情况,例如返回错误信息
  64. $message = '发现违禁词: '. $badWord;
  65. return $this->response->json(
  66. [
  67. 'code' => 0,
  68. 'data' => [],
  69. 'message' => $message
  70. ]
  71. );
  72. }
  73. }
  74. }
  75. return $handler->handle($request);
  76. }catch (\Exception $e){
  77. return $this->response->json(
  78. [
  79. 'code' => $e->getCode(),
  80. 'data' => [],
  81. 'message' => '敏感词检测失败:'.$e->getMessage(),
  82. ]
  83. );
  84. }
  85. return false;
  86. }
  87. }